CVE-2025-31282

CVSS 3.1 Score 4.6 of 10 (medium)

Details

Published Apr 2, 2025
Updated: Apr 7, 2025
CWE ID 269

Summary

CVE-2025-31282 is an access control vulnerability that was identified in the Trend Vision One User Account component. This issue allowed administrators to create new users with elevated privileges, which could then be used to change the role of existing accounts and ultimately escalate privileges. This vulnerability has already been addressed on the backend service and is no longer considered an active threat. However, it underscores the importance of implementing robust access control measures to prevent unauthorized privilege escalation.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share