CVE-2025-6723

MEDIUM

Chef InSpec <5.23 - Privilege Escalation

Title source: llm
STIX 2.1

Description

Chef InSpec versions up to 5.23 and before 7.0.107 creates named pipes with overly permissive default Windows access controls. A local attacker may interfere with the pipe connection process and exploit the insufficient access restrictions to assume the InSpec execution context, potentially resulting in elevated privileges or operational disruption. This issue affects Chef Inspec: through 5.23 and before 7.0.107

Scores

CVSS v4 5.8
EPSS 0.0001
EPSS Percentile 0.4%
CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-269 CWE-287
Status published
Products (1)
Progress Software/Chef Inspec < <=5.23, <7.0.107
Published Jan 30, 2026
Tracked Since Feb 18, 2026