PT-2025-43416 · Mongodb · Mongodb Atlas Sql Odbc Driver
Published
2025-10-22
·
Updated
2025-10-28
·
CVE-2025-11575
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
MongoDB Atlas SQL ODBC driver versions 1.0.0 through 2.0.0
Description
An incorrect default permissions issue exists in the MongoDB Atlas SQL ODBC driver on Windows, potentially allowing for privilege escalation. The issue stems from improperly configured permissions during installation, specifically when using the MSI installer, which may result in Access Control Lists (ACLs) being unset on custom installation directories.
Recommendations
Versions 1.0.0 through 2.0.0: Ensure permissions are correctly configured on custom installation directories to prevent unauthorized privilege escalation.
Fix
LPE
Incorrect Default Permissions
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mongodb Atlas Sql Odbc Driver