CVE-2025-23385: High severity JetBrains ReSharper vulnerability
In JetBrains ReSharper before 2024.3.4, 2024.2.8, and 2024.1.7, Rider before 2024.3.4, 2024.2.8, and 2024.1.7, dotTrace before 2024.3.4, 2024.2.8, and 2024.1.7, ETW Host Service before 16.43, Local Privilege Escalation via the ETW Host Service was possible
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-23385?
CVE-2025-23385 is classified as a local privilege escalation vulnerability.
How do I fix CVE-2025-23385?
To mitigate CVE-2025-23385, upgrade JetBrains ReSharper, Rider, dotTrace, or ETW Host Service to the latest versions beyond the affected releases.
Who is affected by CVE-2025-23385?
CVE-2025-23385 affects users of JetBrains ReSharper, Rider, dotTrace, and ETW Host Service versions before 2024.3.4 or 2024.2.8.
What type of vulnerability is CVE-2025-23385?
CVE-2025-23385 is a local privilege escalation vulnerability that allows unauthorized access to system resources.
What does CVE-2025-23385 exploit in JetBrains software?
CVE-2025-23385 exploits the ETW Host Service, allowing attackers to gain elevated privileges on affected systems.