CVE-2025-54394: Medium severity Netwrix Directory Manager vulnerability
Published Aug 7, 2025
·Updated
Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 has Insufficiently Protected Credentials for requests to remote Excel resources.
Affected Software
2 affected components
Netwrix Directory Manager<11.1.25162.02
Netwrix Directory Manager>=11.0.0.0<11.1.25162.02
Event History
Aug 7, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-54394?
CVE-2025-54394 is classified as a critical vulnerability due to insufficiently protected credentials for requests to remote Excel resources.
2
How do I fix CVE-2025-54394?
To fix CVE-2025-54394, upgrade Netwrix Directory Manager to version 11.1.25162.02 or later immediately.
3
What are the risks of not addressing CVE-2025-54394?
Not addressing CVE-2025-54394 can lead to unauthorized access to sensitive Excel resources due to compromised credentials.
4
Which versions of Netwrix Directory Manager are affected by CVE-2025-54394?
CVE-2025-54394 affects Netwrix Directory Manager versions before 11.1.25162.02.
5
Is there a security patch available for CVE-2025-54394?
Yes, a security patch is available by upgrading to Netwrix Directory Manager version 11.1.25162.02 or higher.