CVE-2025-23385
In JetBrains ReSharper before 2024.3.4, 2024.2.8, and 2024.1.7, Rider before 2024.3.4, 2024.2.8, and 2024.1.7, dotTrace before 2024.3.4, 2024.2.8, and 2024.1.7, ETW Host Service before 16.43, Local Privilege Escalation via the ETW Host Service was possible
Scoring
- Severity
- HIGH
- CVSS base score
- 7.8
- CVSS vector
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
- EPSS probability
- 0.14%
- CWE
- CWE-114
- Published
- 2025-01-28
- Last modified
- 2026-03-13
Affected products
- JetBrains ReSharper
- JetBrains ReSharper
- JetBrains ReSharper
- JetBrains Rider
- JetBrains Rider
- JetBrains Rider
- JetBrains dotTrace
- JetBrains dotTrace
Weakness type
Related vulnerabilities
- CVE-2026-26945 — Dell Integrated Dell Remote Access Controller 9, 14G versions prior to 7.00.00.181, 15G and 16G...
- CVE-2026-29046 — TinyWeb: HTTP Header Control Character Injection into CGI Environment
- CVE-2025-36250 — AIX Code Execution
- CVE-2025-36251 — AIX Command Execution
- CVE-2025-46370 — Dell Alienware Command Center 6.x (AWCC), versions prior to 6.10.15.0, contain a Process Control...
- CVE-2025-1950 — IBM Hardware Management Console - Power Systems command execution
- CVE-2024-56347 — IBM AIX command execution
- CVE-2024-56346 — IBM AIX command execution