PT-2026-25677 · Truesec · Lapswebui

CVE-2025-15554

·

Publicado

2026-03-16

·

Atualizado

2026-03-16

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Truesec’s LAPSWebUI versions prior to 2.4
Description The software stores Local Admin Password Solution (LAPS) passwords in the browser cache. An attacker gaining access to a workstation can potentially elevate their privileges by obtaining these disclosed local administrator passwords.
Recommendations Update Truesec’s LAPSWebUI to version 2.4 or later.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-15554

Produtos afetados

Lapswebui