Untrusted search path in System Center allows an authorized attacker to elevate privileges locally.
CVE ID: CVE-2025-27743
CVSS Base Severity: HIGH
CVSS Base Score: 7.8
CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
Vendor: Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product: System Center Virtual Machine Manager 2022, System Center Virtual Machine Manager 2019, System Center Virtual Machine Manager 2025, System Center Data Protection Manager 2025, System Center Data Protection Manager 2022, System Center Data Protection Manager 2019, System Center Orchestrator 2019, System Center Orchestrator 2022, System Center Orchestrator 2025, System Center Service Manager 2019, System Center Service Manager 2022, System Center Service Manager 2025, System Center Operations Manager 2019, System Center Operations Manager 2022, System Center Operations Manager 2025
EPSS Score: 0.1% (probability of being exploited)
EPSS Percentile: 28.93% (scored less or equal to compared to others)
EPSS Date: 2025-04-18 (when was this score calculated)