Back to overview

CVE-2025-67781

CRITICAL
9.9
CVSS 3.1
Description
An issue was discovered in DriveLock 24.1 before 24.1.6, 24.2 before 24.2.7, and 25.1 before 25.1.5. Local unprivileged users can manipulate privileged processes to gain more privileges on Windows computers.

Metadata

CVE ID
CVE-2025-67781
State
PUBLISHED
Assigner
mitre
Reserved
2025-12-12 00:00 UTC
Published
2025-12-17 00:00 UTC
Last updated
2025-12-17 20:41 UTC
Primary CWE
CWE-269
CWE-269 Improper Privilege Management
Vendor / Product
n/a / n/a
Sources
cve.org  ·  NVD

Severity & Metrics

9.9 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
none
Automatable
no
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
n/a n/a n/a
Weakness (CWE)
CWESourceDescription
cna n/a
CWE-269 adp CWE-269 Improper Privilege Management
CVSS scores (1)
ScoreSeverityVersionSourceVector
9.9 CRITICAL 3.1 adp CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Back to overview