Alert icon Keyboard navigation enabled.
Alert icon TAB or Shift+TAB to navigate across. Down ↓ to open menu. ESC to close menu.
Alert icon Down ↓ to select section. Right → to activate. Up ↑ / Down ↓ / Tab to traverse all. ESC to exit.
BeyondTrust
Skip to content Use space or enter to skip.

What can we help you find today?

Instant Results
  • Website Results
  • Technical Documentation

Filter Options

Focus your search

Filtering by

Your recent searches:

Contact Us Chat with Sales Get Support
  • English
  • Deutsch
  • français
  • español
  • 한국어
  • português
  • Home
  • BT25-05 current page
Link copied

BT25-05

Security Advisories

Advisory ID: BT25-05

White chain icon to symbolize the ability to copy a link
Link copied
Check mark to visually show text has been copied
  • CVSSv4 Score: 7.2
  • CVSSv4 Vector AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
  • Severity: High
  • Issue Date: 2025-07-28
  • Updated On: 2025-07-28
  • CVE(s): CVE-2025-2297
  • CWE: CWE-268
  • Synopsis: Privilege Management for Windows – Elevation of Privilege
  • Impacted: Privilege Management for Windows

Summary

White chain icon to symbolize the ability to copy a link
Link copied
Check mark to visually show text has been copied

A vulnerability has been discovered in Privilege Management for Windows that allows for a local authenticated attacker to elevate privileges.

Details

White chain icon to symbolize the ability to copy a link
Link copied
Check mark to visually show text has been copied

Prior to version 25.4, a local authenticated attacker can manipulate user profile files to add illegitimate challenge response codes into the local user registry under certain conditions. This allows users with the ability to edit their user profile files to elevate their privileges to administrator. This issue has been fixed in version 25.4.270.0

At the time of posting this advisory, all cloud tenants are upgraded to 25.4. Customers can push version 25.4.270.0 to clients to remediate this vulnerability.

Mitigation

White chain icon to symbolize the ability to copy a link
Link copied
Check mark to visually show text has been copied

For versions prior to 25.4.270.0,

  • Avoid using “forever” challenge response auto elevation permissions.
  • Monitor HKEY_USERS\[sid]\Software\Avecto\Privilege Guard Client\ChallengeResponseCache\[sha256sum] for any existing “forever” response entries and make changes to the EPM policy if there are legitimate business needs instead of using forever responses.

Affected Versions

White chain icon to symbolize the ability to copy a link
Link copied
Check mark to visually show text has been copied
Product Version
Privilege Management for Windows Prior to 25.4.270.0

Fixed Versions

White chain icon to symbolize the ability to copy a link
Link copied
Check mark to visually show text has been copied
Product Version
Privilege Management for Windows 25.4.270.0 and later

Known Issues

White chain icon to symbolize the ability to copy a link
Link copied
Check mark to visually show text has been copied

If you encounter issues with domain account authentication after upgrading to version 25.4, we suggest updating to version 25.4.270.0 or newer.

References

White chain icon to symbolize the ability to copy a link
Link copied
Check mark to visually show text has been copied

https://www.cve.org/cverecord?id=CVE-2025-2297

https://nvd.nist.gov/vuln/detail/CVE-2025-2297

https://beyondtrustcorp.service-now.com/csm?id=kb_article_view&sysparm_article=KB0022476

Acknowledgements

White chain icon to symbolize the ability to copy a link
Link copied
Check mark to visually show text has been copied

We would like to thank Lukasz Piotrowski and Marius Kotlarz for reporting this vulnerability responsibly.

Keep up with BeyondTrust

Customer Support Get Started
  • LinkedIn
  • X
  • Facebook
  • Instagram
  • Add BeyondTrust as a preferred source on Google
  • Privacy
  • Security
  • Manage Cookies
  • Do Not Sell My Data
  • WEEE Compliance

Copyright © 2003 — 2026 BeyondTrust Corporation. All rights reserved. Other trademarks identified on this page are owned by their respective owners. BeyondTrust Corporation is not a chartered bank or trust company, or depository institution. It is not authorized to accept deposits or trust accounts and is not licensed or regulated by any state or federal banking authority.

Prefers reduced motion setting detected. Animations will now be reduced as a result.