7.8
CVE-2025-27743
- EPSS 0.84%
- Veröffentlicht 08.04.2025 17:23:25
- Zuletzt bearbeitet 10.07.2025 15:13:40
- Erkennungen
Microsoft System Center Elevation of Privilege Vulnerability
Untrusted search path in System Center allows an authorized attacker to elevate privileges locally.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ System Center Data Protection Manager Version 2019 Update -
Microsoft ≫ System Center Data Protection Manager Version 2022 Update -
Microsoft ≫ System Center Data Protection Manager Version 2025 Update -
Microsoft ≫ System Center Operations Manager Version 2019 Update -
Microsoft ≫ System Center Operations Manager Version 2022 Update -
Microsoft ≫ System Center Operations Manager Version 2025 Update -
Microsoft ≫ System Center Orchestrator Version 2019 Update -
Microsoft ≫ System Center Orchestrator Version 2022 Update -
Microsoft ≫ System Center Orchestrator Version 2025 Update -
Microsoft ≫ System Center Service Manager Version 2019 Update -
Microsoft ≫ System Center Service Manager Version 2022 Update -
Microsoft ≫ System Center Service Manager Version 2025 Update -
Microsoft ≫ System Center Virtual Machine Manager Version 2019 Update -
Microsoft ≫ System Center Virtual Machine Manager Version 2022 Update -
Microsoft ≫ System Center Virtual Machine Manager Version 2025 Update -
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.84% | 0.547 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| Microsoft | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
CWE-426 Untrusted Search Path
The product searches for critical resources using an externally-supplied search path that can point to resources that are not under the product's direct control.
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-27743