PT-2025-31114 · Unknown · User Registry
Lukasz Piotrowski
+1
·
Published
2025-07-28
·
Updated
2025-08-04
·
CVE-2025-2297
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Versions prior to 25.4.270.0
Description
A local authenticated attacker can manipulate user profile files to add illegitimate challenge response codes into the local user registry under certain conditions. This allows users with the ability to edit their user profile files to elevate their privileges to administrator.
Recommendations
Update to version 25.4.270.0 or later.
Fix
LPE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
User Registry