PT-2025-8230 · Unknown · Privilege Management For Windows

Published

2025-02-26

·

Updated

2025-07-31

·

CVE-2025-0889

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Privilege Management for Windows versions prior to 25.2
Description A local authenticated attacker can elevate privileges on a system via the manipulation of COM objects under certain circumstances where an EPM policy allows for automatic privilege elevation of a user process.
Recommendations For versions prior to 25.2, update to version 25.2 or later to resolve the issue. As a temporary workaround, consider restricting the automatic privilege elevation of user processes in EPM policies to minimize the risk of exploitation.

Fix

LPE

Weakness Enumeration

Related Identifiers

CVE-2025-0889

Affected Products

Privilege Management For Windows