Input Validation Flaw in StrongDM Windows Service
CVE-2025-6181

8.5HIGH

Key Information:

Vendor

Strongdm

Status
Vendor
CVE Published:
20 August 2025

What is CVE-2025-6181?

The StrongDM Windows service is susceptible to an input validation error, which allows authenticated attackers to exploit this vulnerability. Successful exploitation could lead to privilege escalation, enabling attackers to gain unauthorized access to restricted areas of the system. Proper input validation mechanisms are crucial in preventing such vulnerabilities and ensuring robust security measures.

Affected Version(s)

sdm-cli Windows 0 <= 47.38.0

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.