CVE-2025-2297 - CVE House
Back to Database
Status published High CVE-2025-2297

Privilege Management for Windows - Elevation of Privilege

Vulnerability Description

Prior to version 25.4.270.0, a local authenticated attacker can manipulate user profile files to add illegitimate challenge response codes into the local user registry under certain conditions. This allows users with the ability to edit their user profile files to elevate their privileges to administrator.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-2297

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Lukasz Piotrowski
  • Marius Kotlarz

Affected Vendor

BeyondTrust

View all reports →

Affected Software

Privilege Management for Windows
Vulnerable Versions:
0

Timeline

Official Publish: July 28th, 2025
Last Modified: July 28th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.