PT-2025-31114 · Unknown · User Registry

·

CVE-2025-2297

·

Published

2025-07-28

·

Updated

2025-08-04

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Versions prior to 25.4.270.0
Description A local authenticated attacker can manipulate user profile files to add illegitimate challenge response codes into the local user registry under certain conditions. This allows users with the ability to edit their user profile files to elevate their privileges to administrator.
Recommendations Update to version 25.4.270.0 or later.

Fix

LPE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-2297

Affected Products

User Registry