CVE-2025-64456: High severity JetBrains ReSharper vulnerability
Published Nov 10, 2025
·Updated
In JetBrains ReSharper before 2025.2.4 missing signature verification in DPA Collector allows local privilege escalation
Affected Software
2 affected components
JetBrains ReSharper<2025.2.4
JetBrains ReSharper<2025.2.4
Event History
Nov 10, 2025
CVE Published
via MITRE·01:28 PM
Data Sourced
via MITRE·01:28 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-64456?
CVE-2025-64456 is classified as a high severity vulnerability due to its potential for local privilege escalation.
2
How do I fix CVE-2025-64456?
To mitigate CVE-2025-64456, update JetBrains ReSharper to version 2025.2.4 or later.
3
What causes CVE-2025-64456?
CVE-2025-64456 is caused by a missing signature verification in the DPA Collector component of JetBrains ReSharper.
4
Who is affected by CVE-2025-64456?
CVE-2025-64456 affects all versions of JetBrains ReSharper prior to 2025.2.4.
5
Can CVE-2025-64456 be exploited remotely?
CVE-2025-64456 cannot be exploited remotely as it requires local access to the affected system.