CVE-2025-23181

CVSS 3.1 Score 8 of 10 (high)

Details

Published Apr 29, 2025
Updated: May 2, 2025
CWE ID 250

Summary

CVE-2025-23181 is a newly disclosed cybersecurity vulnerability, identified as CWE-250: Execution with Unnecessary Privileges. This issue arises when a software runs with elevated privileges even when they are not required for its intended functionality. An attacker could exploit this vulnerability to gain unauthorized access or execute malicious code with elevated privileges, potentially leading to significant security consequences. The precise consequences depend on the specific software affected and the attacker's intentions. It is crucial for affected organizations to apply the necessary patches or mitigations to minimize the risk of exploitation.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share