nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-2297 CVE-2025-2297
HIGH
Privilege Management for Windows - Elevation of Privilege
Record summary
CVE-2025-2297 has a selected CVSS score of 7.2 (high).
Description
Prior to version 25.4.270.0, a local authenticated attacker can manipulate user profile files to add illegitimate challenge response codes into the local user registry under certain conditions. This allows users with the ability to edit their user profile files to elevate their privileges to administrator.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 28, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Privilege Management for WindowsBrowse BeyondTrust / Privilege Management for WindowsDefault status: unaffected | CVE List | Before <25.4.270 | affected |
References
2beyondtrust.com
https://www.beyondtrust.com/trust-center/security-advisories/bt25-05