nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-6250 CVE-2025-6250
HIGH
Privilege Management for Windows - Elevation of Privilege
Record summary
CVE-2025-6250 has a selected CVSS score of 7.1 (high).
Description
Prior to 25.4.270.0, when wmic.exe is elevated with a full admin token the user can stop the Defendpoint service, bypassing anti-tamper protections. Once the service is disabled, the malicious user can add themselves to Administrators group and run any process with elevated permissions.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 28, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Privilege Management for WindowsBrowse BeyondTrust / Privilege Management for WindowsDefault status: unaffected | CVE List | Before <25.4.270 | affected |
References
2beyondtrust.com
https://www.beyondtrust.com/trust-center/security-advisories/bt25-06