216.73.217.22

CVE-2025-6250

· Published 28/07/2025 16:15 · Modified 29/07/2025 14:14

Labels: CVE-2025-6250 13061848-ea10-403d-bd75-c83a022c28912025-07-28CVE-2025-6250CWE-424

Essential information

Published
28/07/2025 16:15
Modified
29/07/2025 14:14
Author
Creator
CVSS
7.1 HIGH (v3) 7.1 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Prior to 25.4.270.0, when wmic.exe is elevated with a full admin token the user can stop the Defendpoint service, bypassing anti-tamper protections. Once the service is disabled, the malicious user can add themselves to Administrators group and run any process with elevated permissions.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
13061848-ea10-403d-bd75-c83a022c2891
NVD
View on NVD

Affected products (CPE)

ProductCPE
wmic / wmic cpe:2.3:a:wmic:wmic:*:*:*:*:*:*:*:*
defendpoint / defendpoint cpe:2.3:a:defendpoint:defendpoint:*:*:*:*:*:*:*:*

References