PT-2025-31114 · Unknown · User Registry

Lukasz Piotrowski

+1

·

Published

2025-07-28

·

Updated

2025-08-04

·

CVE-2025-2297

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Versions prior to 25.4.270.0
Description A local authenticated attacker can manipulate user profile files to add illegitimate challenge response codes into the local user registry under certain conditions. This allows users with the ability to edit their user profile files to elevate their privileges to administrator.
Recommendations Update to version 25.4.270.0 or later.

Fix

LPE

Weakness Enumeration

Related Identifiers

CVE-2025-2297

Affected Products

User Registry