CVE-2025-6182

HIGH

StrongDM sdm < 47.49.0 - Improper Privilege Management via Certificate Handling

Title source: llm
STIX 2.1

Description

The StrongDM Windows service incorrectly handled communication related to system certificate management. Attackers could exploit this behavior to install untrusted root certificates or remove trusted ones.

References (1)

Core 1

Scores

CVSS v4 8.5
EPSS 0.0008
EPSS Percentile 0.1%
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-269
Status published
Products (1)
StrongDM/sdm < 47.49.0
Published Aug 20, 2025
Tracked Since Feb 18, 2026