CVE-2025-0327
CVSS 3.1 Score 7.8 of 10 (high)
Details
Published Feb 13, 2025
CWE ID 269
Summary
CVE-2025-0327 represents a privilege management vulnerability affecting two Windows services, one handling audit trail data and the other managing client requests. An attacker with standard privileges can exploit this CWE-269 weakness by modifying the executable path of these services, leading to potential loss of Confidentiality, Integrity, and Availability for engineering workstations. Exploitation necessitates a service restart.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- EcoStruxure Process Expert
Affected Vendors
- Schneider Electric SE