CVE Database
/

CVE-2025-0889

Back to search

CVE-2025-0889

Published: Feb 26, 2025

Modified: Feb 26, 2025

PUBLISHED

Description

Prior to 25.2, a local authenticated attacker can elevate privileges on a system with Privilege Management for Windows installed, via the manipulation of COM objects under certain circumstances where an EPM policy allows for automatic privilege elevation of a user process.

VendorProductVersions

BeyondTrust

Privilege Management for Windows

affected
0 - < 25.2

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now