CVE-2025-23528

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Jan 16, 2025
CWE ID 266

Summary

CVE-2025-23528 is an Incorrect Privilege Assignment vulnerability affecting DD Roles, from an undisclosed version through 4.1. This issue grants Privilege Escalation, enabling unauthorized users to gain elevated access to sensitive information or functionalities within the affected system. The vulnerability stems from incorrect privilege assignments within DD Roles, creating a potential security risk for organizations using this software solution. It is crucial for users to update to a patched version as soon as possible to mitigate this vulnerability and prevent potential attacks.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share