labs.reversec.com
https://labs.reversec.com/advisories/2026/03/admin-passwords-cached-by-browsers-in-truesec-lapswebui CVE-2025-15554
MEDIUM
Admin Passwords Cached by Browsers in Truesec LAPSWebUI
Record summary
CVE-2025-15554 has a selected CVSS score of 6.0 (medium).
Description
Browser caching of LAPS passwords in Truesec’s LAPSWebUI before version 2.4 allows an attacker with access to a workstation to escalate their privileges via disclosure of local admin passwords.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 16, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
LAPSWebUIBrowse Truesec / LAPSWebUIDefault status: unaffected | CVE List | Before 2.4 | affected |
| 2.4 | unaffected |
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-15554