Record summary

CVE-2025-0327 has a selected CVSS score of 8.5 (high).

Description

CWE-269: Improper Privilege Management vulnerability exists for two services (of which one managing audit trail data and the other acting as server managing client request) that could cause a loss of Confidentiality, Integrity and Availability of engineering workstation when an attacker with standard privilege modifies the executable path of the windows services. To be exploited, services need to be restarted.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 13, 2025 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

Default status: unaffected

CVE ListVersions 2020R2affected
Versions 2021 & 2023 (prior to v4.8.0.5715)affected

Default status: unaffected

CVE ListVersions 2020R2affected
Versions 2021 & 2023affected

References

2