216.73.217.22

CVE-2025-0867

· Published 14/02/2025 13:15 · Modified 14/02/2025 13:15

Labels: CVE-2025-0867 2025-02-14CVE-2025-0867CWE-522[email protected]

Essential information

Published
14/02/2025 13:15
Modified
14/02/2025 13:15
Author
Creator
CVSS
9.9 CRITICAL (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

CVSS metrics

Description

The standard user uses the run as function to start the MEAC applications with administrative privileges. To ensure that the system can startup on its own, the credentials of the administrator were stored. Consequently, the EPC2 user can execute any command with administrative privileges. This allows a privilege escalation to the administrative level.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

References