ZDI-25-1045: Schneider Electric PowerChute Serial Shutdown Directory Traversal Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Schneider Electric PowerChute Serial Shutdown. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. Additionally, the attacker must authenticate to the application. The ZDI has assigned a CVSS rating of 6.7. The following CVEs are assigned: CVE-2025-11565, CVE-2025-11566, CVE-2025-11567.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-25-1045?
The ZDI-25-1045 vulnerability has a significant severity level due to its potential for privilege escalation.
How do I fix ZDI-25-1045?
To fix ZDI-25-1045, ensure that you apply the latest security patches provided by Schneider Electric for PowerChute Serial Shutdown.
Who is affected by ZDI-25-1045?
ZDI-25-1045 affects installations of Schneider Electric PowerChute Serial Shutdown software.
What type of attacks can be performed using ZDI-25-1045?
ZDI-25-1045 can be exploited by local attackers to escalate their privileges on the affected system.
What is required to exploit ZDI-25-1045?
An attacker must first have the ability to execute low-privileged code on the target system to exploit ZDI-25-1045.