Privilege Escalation in MongoDB Atlas SQL ODBC Driver on Windows
CVE-2025-11575

8.8HIGH

Key Information:

Vendor

Mongodb

Vendor
CVE Published:
23 October 2025

What is CVE-2025-11575?

A security vulnerability exists in the MongoDB Atlas SQL ODBC driver on Windows due to incorrect default permissions. This flaw can allow attackers to escalate privileges, potentially leading to unauthorized access or modifications. The vulnerability impacts versions 1.0.0 through 2.0.0 of the driver, necessitating timely updates and security measures to protect user data and system integrity.

Affected Version(s)

Atlas SQL ODBC driver Windows 1.0.0 <= 2.0.0

References

CVSS V4

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-11575 : Privilege Escalation in MongoDB Atlas SQL ODBC Driver on Windows