CVE-2025-0327

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Feb 13, 2025
CWE ID 269

Summary

CVE-2025-0327 represents a privilege management vulnerability affecting two Windows services, one handling audit trail data and the other managing client requests. An attacker with standard privileges can exploit this CWE-269 weakness by modifying the executable path of these services, leading to potential loss of Confidentiality, Integrity, and Availability for engineering workstations. Exploitation necessitates a service restart.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • EcoStruxure Process Expert

Affected Vendors

  • Schneider Electric SE