nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-0889 CVE-2025-0889
HIGH
Privilege Management for Windows – Elevation of Privilege
Record summary
CVE-2025-0889 has a selected CVSS score of 7.2 (high).
Description
Prior to 25.2, a local authenticated attacker can elevate privileges on a system with Privilege Management for Windows installed, via the manipulation of COM objects under certain circumstances where an EPM policy allows for automatic privilege elevation of a user process.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 26, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Privilege Management for WindowsBrowse BeyondTrust / Privilege Management for WindowsDefault status: unaffected | CVE List | Before 25.2 | affected |
References
2beyondtrust.com
https://www.beyondtrust.com/trust-center/security-advisories/bt25-01