CVE-2025-2297: Privilege Management for Windows - Elevation of Privilege
Prior to version 25.4.270.0, a local authenticated attacker can manipulate user profile files to add illegitimate challenge response codes into the local user registry under certain conditions. This allows users with the ability to edit their user profile files to elevate their privileges to administrator.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-2297?
CVE-2025-2297 is considered a high-severity vulnerability due to the potential for privileged escalation by authenticated local attackers.
How do I fix CVE-2025-2297?
To fix CVE-2025-2297, update Microsoft Privilege Management for Windows to version 25.4.270.0 or later.
Who is affected by CVE-2025-2297?
CVE-2025-2297 affects users of Microsoft Privilege Management for Windows prior to version 25.4.270.0.
What type of attack does CVE-2025-2297 enable?
CVE-2025-2297 enables local authenticated attackers to manipulate user profile files to elevate their privileges.
What conditions must be met for CVE-2025-2297 to be exploited?
CVE-2025-2297 can only be exploited if a local authenticated user has the ability to edit their own user profile files.