Untrusted search path in System Center allows an authorized attacker to elevate privileges locally.
History

Thu, 10 Jul 2025 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft
Microsoft system Center Data Protection Manager
Microsoft system Center Operations Manager
Microsoft system Center Orchestrator
Microsoft system Center Service Manager
Microsoft system Center Virtual Machine Manager
CPEs cpe:2.3:a:microsoft:system_center_data_protection_manager:2019:-:*:*:*:*:*:*
cpe:2.3:a:microsoft:system_center_data_protection_manager:2022:-:*:*:*:*:*:*
cpe:2.3:a:microsoft:system_center_data_protection_manager:2025:-:*:*:*:*:*:*
cpe:2.3:a:microsoft:system_center_operations_manager:2019:-:*:*:*:*:*:*
cpe:2.3:a:microsoft:system_center_operations_manager:2022:-:*:*:*:*:*:*
cpe:2.3:a:microsoft:system_center_operations_manager:2025:-:*:*:*:*:*:*
cpe:2.3:a:microsoft:system_center_orchestrator:2019:-:*:*:*:*:*:*
cpe:2.3:a:microsoft:system_center_orchestrator:2022:-:*:*:*:*:*:*
cpe:2.3:a:microsoft:system_center_orchestrator:2025:-:*:*:*:*:*:*
cpe:2.3:a:microsoft:system_center_service_manager:2019:-:*:*:*:*:*:*
cpe:2.3:a:microsoft:system_center_service_manager:2022:-:*:*:*:*:*:*
cpe:2.3:a:microsoft:system_center_service_manager:2025:-:*:*:*:*:*:*
cpe:2.3:a:microsoft:system_center_virtual_machine_manager:2019:-:*:*:*:*:*:*
cpe:2.3:a:microsoft:system_center_virtual_machine_manager:2022:-:*:*:*:*:*:*
cpe:2.3:a:microsoft:system_center_virtual_machine_manager:2025:-:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft system Center Data Protection Manager
Microsoft system Center Operations Manager
Microsoft system Center Orchestrator
Microsoft system Center Service Manager
Microsoft system Center Virtual Machine Manager

Tue, 08 Apr 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Apr 2025 17:30:00 +0000

Type Values Removed Values Added
Description Untrusted search path in System Center allows an authorized attacker to elevate privileges locally.
Title Microsoft System Center Elevation of Privilege Vulnerability
Weaknesses CWE-426
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published: 2025-04-08T17:23:25.628Z

Updated: 2025-06-04T17:52:40.439Z

Reserved: 2025-03-06T04:26:08.553Z

Link: CVE-2025-27743

cve-icon Vulnrichment

Updated: 2025-04-08T19:57:44.615Z

cve-icon NVD

Status : Analyzed

Published: 2025-04-08T18:16:03.260

Modified: 2025-07-10T15:13:40.693

Link: CVE-2025-27743

cve-icon Redhat

No data.