Untrusted search path in Microsoft products - CVE-2025-27743

 

Untrusted search path in Microsoft products - CVE-2025-27743

Published: April 8, 2025


Vulnerability identifier: #VU107160
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-27743
CWE-ID: CWE-426
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to usage of an untrusted search path in Microsoft System Center. A local user can gain elevated privileges on the target system.


Affected software

Microsoft System Center Operations Manager
System Center Service Manager
System Center Orchestrator
System Center Data Protection Manager
System Center Virtual Machine Manager

How to mitigate CVE-2025-27743

Install updates from vendor's website.


External References

Related Security Bulletins