Security Advisory

CVE-2025-0889

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2025-02-26 01:41:25
Last updated 2025-02-26 15:43:14
Assigner BT
State PUBLISHED

Description

Prior to 25.2, a local authenticated attacker can elevate privileges on a system with Privilege Management for Windows installed, via the manipulation of COM objects under certain circumstances where an EPM policy allows for automatic privilege elevation of a user process.