Elevated Privilege Vulnerability in Defendpoint Service by BeyondTrust
CVE-2025-6250
7.1HIGH
What is CVE-2025-6250?
Prior to version 25.4.270.0, the Defendpoint service by BeyondTrust is vulnerable due to improper privilege management. When the wmic.exe process is executed with elevated administrative rights, it can stop the Defendpoint service, effectively bypassing the built-in anti-tamper protections. This vulnerability allows malicious users to disable essential security features, add themselves to the Administrators group, and execute any process with elevated permissions, posing a significant threat to system integrity and security.
Affected Version(s)
Privilege Management for Windows 0