CVE-2025-2272: Privilege Escalation and Arbitrary code execution in F1E Endpoint
Published May 22, 2025
·Updated
Uncontrolled Search Path Element vulnerability in Forcepoint FIE Endpoint allows Privilege Escalation, Code Injection, Hijacking a privileged process.This issue affects FIE Endpoint: before 25.05.
Affected Software
1 affected component
Forcepoint FIE Endpoint<25.05
Remediation
Information
Update to F1E
25.05
Event History
May 22, 2025
CVE Published
via MITRE·12:23 PM
Data Sourced
via MITRE·12:23 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-2272?
CVE-2025-2272 has a high severity rating due to its potential for privilege escalation and code injection.
2
How do I fix CVE-2025-2272?
To mitigate CVE-2025-2272, update Forcepoint FIE Endpoint to version 25.05 or later.
3
What kind of attacks can CVE-2025-2272 enable?
CVE-2025-2272 can enable attacks such as privilege escalation, code injection, and hijacking of privileged processes.
4
Which software versions are affected by CVE-2025-2272?
CVE-2025-2272 affects versions of Forcepoint FIE Endpoint before 25.05.
5
Is CVE-2025-2272 a critical vulnerability?
While CVE-2025-2272 is not classified as critical, its ability to allow privilege escalation makes it a significant security concern.