Elevated Privilege Vulnerability in Defendpoint Service by BeyondTrust
CVE-2025-6250

7.1HIGH

Key Information:

Vendor
CVE Published:
28 July 2025

What is CVE-2025-6250?

Prior to version 25.4.270.0, the Defendpoint service by BeyondTrust is vulnerable due to improper privilege management. When the wmic.exe process is executed with elevated administrative rights, it can stop the Defendpoint service, effectively bypassing the built-in anti-tamper protections. This vulnerability allows malicious users to disable essential security features, add themselves to the Administrators group, and execute any process with elevated permissions, posing a significant threat to system integrity and security.

Affected Version(s)

Privilege Management for Windows 0

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

MSG Systems AG
.
CVE-2025-6250 : Elevated Privilege Vulnerability in Defendpoint Service by BeyondTrust