PT-2025-43416 · Mongodb · Mongodb Atlas Sql Odbc Driver

Published

2025-10-22

·

Updated

2025-10-28

·

CVE-2025-11575

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions MongoDB Atlas SQL ODBC driver versions 1.0.0 through 2.0.0
Description An incorrect default permissions issue exists in the MongoDB Atlas SQL ODBC driver on Windows, potentially allowing for privilege escalation. The issue stems from improperly configured permissions during installation, specifically when using the MSI installer, which may result in Access Control Lists (ACLs) being unset on custom installation directories.
Recommendations Versions 1.0.0 through 2.0.0: Ensure permissions are correctly configured on custom installation directories to prevent unauthorized privilege escalation.

Fix

LPE

Incorrect Default Permissions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-13337
CVE-2025-11575

Affected Products

Mongodb Atlas Sql Odbc Driver