CVE-2025-0712
HIGHUnspecified - Privilege Escalation
Title source: llmDescription
An uncontrolled search path element vulnerability can lead to local privilege Escalation (LPE) via Insecure Directory Permissions. The vulnerability arises from improper handling of directory permissions. An attacker with local access may exploit this flaw to move and delete arbitrary files, potentially gaining SYSTEM privileges.
Scores
CVSS v3
7.0
EPSS
0.0001
EPSS Percentile
1.5%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-427
Status
draft
Timeline
Published
Jul 30, 2025
Tracked Since
Feb 18, 2026