CVE-2025-27743: Microsoft System Center Elevation of Privilege Vulnerability

7.8 CVSS

Description

Untrusted search path in System Center allows an authorized attacker to elevate privileges locally.

Classification

CVE ID: CVE-2025-27743

CVSS Base Severity: HIGH

CVSS Base Score: 7.8

CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C

Problem Types

CWE-426: Untrusted Search Path

Affected Products

Vendor: Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft

Product: System Center Virtual Machine Manager 2022, System Center Virtual Machine Manager 2019, System Center Virtual Machine Manager 2025, System Center Data Protection Manager 2025, System Center Data Protection Manager 2022, System Center Data Protection Manager 2019, System Center Orchestrator 2019, System Center Orchestrator 2022, System Center Orchestrator 2025, System Center Service Manager 2019, System Center Service Manager 2022, System Center Service Manager 2025, System Center Operations Manager 2019, System Center Operations Manager 2022, System Center Operations Manager 2025

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.1% (probability of being exploited)

EPSS Percentile: 28.93% (scored less or equal to compared to others)

EPSS Date: 2025-04-18 (when was this score calculated)

References

https://nvd.nist.gov/vuln/detail/CVE-2025-27743
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-27743

Timeline