CVE-2025-11575: MongoDB Atlas SQL ODBC driver installation via MSI may leave ACLs unset on custom installation directories
Published Oct 23, 2025
·Updated
Incorrect Default Permissions vulnerability in MongoDB Atlas SQL ODBC driver on Windows allows Privilege Escalation.This issue affects MongoDB Atlas SQL ODBC driver: from 1.0.0 through 2.0.0.
Affected Software
1 affected component
MongoDB Atlas SQL ODBC driver>=1.0.0<=2.0.0
Event History
Oct 23, 2025
CVE Published
via MITRE·12:22 AM
Data Sourced
via MITRE·12:22 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-11575?
CVE-2025-11575 is classified as a privilege escalation vulnerability.
2
How do I fix CVE-2025-11575?
To fix CVE-2025-11575, upgrade the MongoDB Atlas SQL ODBC driver to version 2.0.1 or later.
3
Which versions of MongoDB Atlas SQL ODBC driver are affected by CVE-2025-11575?
CVE-2025-11575 affects MongoDB Atlas SQL ODBC driver versions from 1.0.0 through 2.0.0.
4
What platform is impacted by CVE-2025-11575?
CVE-2025-11575 impacts the Windows platform specifically.
5
Is there a workaround for CVE-2025-11575?
Currently, the recommended action is to upgrade to the latest version, as no effective workaround is available.