Privilege Elevation Vulnerability in Microsoft System Center
CVE-2025-27743
7.8HIGH
Key Information:
- Vendor
- Microsoft
- Status
- Vendor
- CVE Published:
- 8 April 2025
Summary
A vulnerability has been identified in Microsoft System Center that involves an untrusted search path, which allows an authorized attacker to gain elevated privileges on affected systems. When successfully exploited, this weakness can enable attackers to execute arbitrary code with elevated rights, potentially compromising sensitive information and system integrity.
Affected Version(s)
System Center Data Protection Manager 2019 Unknown
System Center Data Protection Manager 2022 Unknown
System Center Data Protection Manager 2025 Unknown
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved