CVE-2025-27743: Microsoft System Center Elevation of Privilege Vulnerability
Microsoft System Center Elevation of Privilege Vulnerability
Other sources
Untrusted search path in System Center allows an authorized attacker to elevate privileges locally.
— Microsoft
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-27743?
CVE-2025-27743 has a severity rating of important due to its potential to allow privilege escalation.
How do I fix CVE-2025-27743?
To fix CVE-2025-27743, apply the security updates provided by Microsoft for affected System Center products.
Which products are affected by CVE-2025-27743?
CVE-2025-27743 affects multiple Microsoft products including System Center Orchestrator, Data Protection Manager, Virtual Machine Manager, and Service Manager.
Can an authorized attacker exploit CVE-2025-27743?
Yes, an authorized attacker can exploit CVE-2025-27743 to elevate their privileges locally within the affected System Center products.
Is there a workaround for CVE-2025-27743?
Currently, Microsoft recommends applying the latest updates as the primary mitigation for CVE-2025-27743, with no listed workarounds.