Local privilege escalation through insecure DCOM configuration in Valmet DNA versions prior to C2023. The DCOM object Valmet DNA Engineering has permissions that allow it to run commands as a user with the SeImpersonatePrivilege privilege. The SeImpersonatePrivilege privilege is a Windows permission that allows a process to impersonate another user. An attacker can use this vulnerability to escalate their privileges and take complete control of the system.
Metrics
Affected Vendors & Products
References
History
Tue, 01 Apr 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 01 Apr 2025 04:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Local privilege escalation through insecure DCOM configuration in Valmet DNA versions prior to C2023. The DCOM object Valmet DNA Engineering has permissions that allow it to run commands as a user with the SeImpersonatePrivilege privilege. The SeImpersonatePrivilege privilege is a Windows permission that allows a process to impersonate another user. An attacker can use this vulnerability to escalate their privileges and take complete control of the system. | |
| Title | Valmet DNA Local privilege escalation through insecure DCOM configuration | |
| Weaknesses | CWE-269 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: NCSC-FI
Published: 2025-04-01T04:05:14.236Z
Updated: 2025-04-01T14:13:36.829Z
Reserved: 2025-01-13T12:24:09.743Z
Link: CVE-2025-0416
Updated: 2025-04-01T14:13:32.247Z
Status : Awaiting Analysis
Published: 2025-04-01T04:15:37.727
Modified: 2025-04-01T20:26:11.547
Link: CVE-2025-0416
No data.