Local Authentication Vulnerability in BeyondTrust Privilege Management
CVE-2025-2297
7.2HIGH
What is CVE-2025-2297?
Prior to version 25.4.270.0, a vulnerability exists in BeyondTrust Privilege Management that allows local authenticated attackers to manipulate user profile files. This manipulation enables the insertion of illegitimate challenge response codes into the user's local registry under specific conditions. Users with the capability to edit their profile files could exploit this flaw to elevate their privileges to that of an administrator, potentially compromising the integrity of the system.
Affected Version(s)
Privilege Management for Windows 0
References
CVSS V4
Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Lukasz Piotrowski
Marius Kotlarz
