CVE-2025-4235: User-ID Credential Agent: Cleartext Exposure of Service Account password (Severity: MEDIUM)
An information exposure vulnerability in the Palo Alto Networks User-ID Credential Agent (Windows-based) can expose the service account password under specific non-default configurations. This allows an unprivileged Domain User to escalate privileges by exploiting the account’s permissions. The impact varies by configuration:
Minimally Privileged Accounts: Enable disruption of User-ID Credential Agent operations (e.g., uninstalling or disabling the agent service), weakening network security policies that leverage Credential Phishing Prevention (https://docs.paloaltonetworks.com/advanced-url-filtering/administration/url-filtering-features/credential-phishing-prevention) under a Domain Credential Filter (https://docs.paloaltonetworks.com/advanced-url-filtering/administration/url-filtering-features/credential-phishing-prevention/methods-to-check-for-corporate-credential-submissions) configuration. Elevated Accounts (Server Operator, Domain Join, Legacy Features): Permit increased impacts, including server control (e.g., shutdown/restart), domain manipulation (e.g., rogue computer objects), and network compromise via reconnaissance or client probing.
Other sources
An information exposure vulnerability in the Palo Alto Networks User-ID Credential Agent (Windows-based) can expose the service account password under specific non-default configurations. This allows an unprivileged Domain User to escalate privileges by exploiting the account’s permissions. The impact varies by configuration: Minimally Privileged Accounts: Enable disruption of User-ID Credential Agent operations (e.g., uninstalling or disabling the agent service), weakening network security policies that leverage Credential Phishing Prevention https://docs.paloaltonetworks.com/advanced-url-filtering/administration/url-filtering-features/credential-phishing-prevention under a Domain Credential Filter https://docs.paloaltonetworks.com/advanced-url-filtering/administration/url-filtering-features/credential-phishing-prevention/methods-to-check-for-corporate-credential-submissions configuration. Elevated Accounts (Server Operator, Domain Join, Legacy Features): Permit increased impacts, including server control (e.g., shutdown/restart), domain manipulation (e.g., rogue computer objects), and network compromise via reconnaissance or client probing.
— MITRE
Affected Software
Remediation
Mitigation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-4235?
CVE-2025-4235 has been categorized as a high severity vulnerability due to its potential to expose sensitive credentials.
How do I fix CVE-2025-4235?
To mitigate CVE-2025-4235, ensure that the User-ID Credential Agent is configured with the default security best practices to avoid exposing service account passwords.
Who is affected by CVE-2025-4235?
CVE-2025-4235 affects users of the Palo Alto Networks User-ID Credential Agent when specific non-default configurations are applied.
What are the potential consequences of CVE-2025-4235?
Exploitation of CVE-2025-4235 may allow unprivileged Domain Users to escalate privileges by accessing the service account password.
Can CVE-2025-4235 be exploited remotely?
CVE-2025-4235 requires specific local conditions and configurations to be exploited, making remote exploitation less likely.