Local Authentication Vulnerability in BeyondTrust Privilege Management
CVE-2025-2297
7.2HIGH
What is CVE-2025-2297?
Prior to version 25.4.270.0, a vulnerability exists in BeyondTrust Privilege Management that allows local authenticated attackers to manipulate user profile files. This manipulation enables the insertion of illegitimate challenge response codes into the user's local registry under specific conditions. Users with the capability to edit their profile files could exploit this flaw to elevate their privileges to that of an administrator, potentially compromising the integrity of the system.
Affected Version(s)
Privilege Management for Windows 0