CVE-2025-0327
CVSS 3.1 Score 7.8 of 10 (high)
Details
Published Feb 13, 2025
CWE ID 269
Summary
CVE-2025-0327 represents a privilege management vulnerability affecting two Windows services, one handling audit trail data and the other managing client requests. An attacker with standard privileges can exploit this CWE-269 weakness by modifying the executable path of these services, leading to potential loss of Confidentiality, Integrity, and Availability for engineering workstations. Exploitation necessitates a service restart.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Products
- EcoStruxure Process Expert
Affected Vendors
- Schneider Electric SE