PT-2025-4868 · Jetbrains · Dottrace+2
Published
2025-01-28
·
Updated
2025-01-28
·
CVE-2025-23385
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
JetBrains ReSharper versions prior to 2024.3.4
JetBrains Rider versions prior to 2024.3.4
dotTrace versions prior to 2024.3.4
ETW Host Service versions prior to 16.43
Description
The issue is related to incorrect process management in the affected software, which can allow an attacker to escalate their privileges. This can be achieved through the ETW Host Service.
Recommendations
For JetBrains ReSharper versions prior to 2024.3.4, update to version 2024.3.4 or later.
For JetBrains Rider versions prior to 2024.3.4, update to version 2024.3.4 or later.
For dotTrace versions prior to 2024.3.4, update to version 2024.3.4 or later.
For ETW Host Service versions prior to 16.43, update to version 16.43 or later.
Fix
LPE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Resharper
Rider
Dottrace