PT-2025-43416 · Mongodb · Mongodb Atlas Sql Odbc Driver
Publicado
2025-10-22
·
Atualizado
2025-10-28
·
CVE-2025-11575
CVSS v3.1
7.8
Alta
| Vetor | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
MongoDB Atlas SQL ODBC driver versions 1.0.0 through 2.0.0
Description
An incorrect default permissions issue exists in the MongoDB Atlas SQL ODBC driver on Windows, potentially allowing for privilege escalation. The issue stems from improperly configured permissions during installation, specifically when using the MSI installer, which may result in Access Control Lists (ACLs) being unset on custom installation directories.
Recommendations
Versions 1.0.0 through 2.0.0: Ensure permissions are correctly configured on custom installation directories to prevent unauthorized privilege escalation.
Correção
LPE
Incorrect Default Permissions
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Mongodb Atlas Sql Odbc Driver