CVE-2025-0889
Prior to 25.2, a local authenticated attacker can elevate privileges on a system with Privilege Management for Windows installed, via the manipulation of COM objects under certain circumstances where an EPM policy allows for automatic privilege elevation of a user process.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.2
- CVSS vector
- CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.20%
- CWE
- CWE-268
- Published
- 2025-02-26
- Last modified
- 2026-03-13
Affected products
- BeyondTrust Privilege Management for Windows
Weakness type
Related vulnerabilities
- CVE-2026-32325 — Privilege chaining issue exists in ServerView Agents for Windows V11.60.04 and earlier. If this...
- CVE-2026-3888 — Local Privilege Escalation in snapd
- CVE-2025-64701 — QND Premium/Advance/Standard Ver.11.0.9i and prior contains a privilege escalation vulnerability,...
- CVE-2025-7973 — Rockwell Automation FactoryTalk® ViewPoint Privilege Escalation Vulnerability
- CVE-2025-36124 — IBM WebSphere Application Server Liberty bypass security
- CVE-2025-2297 — Privilege Management for Windows - Elevation of Privilege
- CVE-2025-49741 — Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
- CVE-2025-20112 — Cisco Unified Communications Products Privilege Escalation Vulnerability