https://seclists.org/oss-sec/2025/q3/244: FeIPA - CVE-2025-7493 - Privilege Escalation from host to domain admin
Published Sep 30, 2025
·Updated
Affected Software
1 affected component
FreeIPA FreeIPA
Frequently Asked Questions
1
What is the severity of CVE-2025-7493?
CVE-2025-7493 is classified as a privilege escalation vulnerability that can lead to unauthorized access to domain admin privileges.
2
How do I fix CVE-2025-7493?
To mitigate CVE-2025-7493, upgrade FreeIPA to the latest version as recommended in the upstream release notes.
3
What causes CVE-2025-7493?
CVE-2025-7493 is caused by incomplete uniqueness checks in the Kerberos implementation within FreeIPA.
4
Who is affected by CVE-2025-7493?
Organizations using vulnerable versions of FreeIPA are at risk of privilege escalation due to CVE-2025-7493.
5
When was CVE-2025-7493 published?
CVE-2025-7493 was published on September 30, 2025.