CVE-2025-31284
CVSS 3.1 Score 4.6 of 10 (medium)
Details
Published Apr 2, 2025
Updated: Apr 7, 2025
CWE ID 269
Summary
CVE-2025-31284 is an access control vulnerability that was discovered in the Trend Vision One Status component. This issue enabled administrators to create new users, who could subsequently alter the roles of other accounts. With this privilege escalation, an attacker could potentially gain unauthorized access to sensitive information or systems. Fortunately, the vulnerability has been resolved on the backend service and is no longer considered an active threat.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.