AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2025-2297

HIGH · CVSS 7.8 EPSS 0.13%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2025-07-28 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 7.8. Exploitation may require the attacker to be authenticated.

CVE
CVE-2025-2297
Severity
HIGH
CVSS
7.8
EPSS
0.13%

Original NVD Description

Prior to version 25.4.270.0, a local authenticated attacker can manipulate user profile files to add illegitimate challenge response codes into the local user registry under certain conditions. This allows users with the ability to edit their user profile files to elevate their privileges to administrator.

Related CVEs

Other vulnerabilities affecting the same vendor(s)