---
cve: "CVE-2025-0327"
severity: "HIGH"
cvss: 8.5
epss: "16%"
vendor: "Schneider Electric"
kev: false
exploited: false
published: "2025-02-13 07:15:10"
tags: [cve, security, high]
source: tsecurity.de CVE-Dossier
exported: "2026-09-06T04:01:19+02:00"
---

# CVE-2025-0327

> 8.5 HIGH

## Beschreibung

CWE-269: Improper Privilege Management vulnerability exists for two services (of which one managing audit
trail data and the other acting as server managing client request) that could cause a loss of Confidentiality,
Integrity and Availability of engineering workstation when an attacker with standard privilege modifies the
executable path of the windows services. To be exploited, services need to be restarted.

## CVSS-Vektor

```
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Lokal | good |
| AC Komplexität | Gering | bad |
| PR Privilegien | Gering | warn |
| UI Interaktion | Keine | bad |

## Schwachstellen-Klasse

- **CWE-269** — Improper Privilege Management
  The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

## Angriffsmuster (CAPEC)

- [CAPEC-58 — Restful Privilege Elevation](https://capec.mitre.org/data/definitions/58.html) _(Severity: High)_
- [CAPEC-122 — Privilege Abuse](https://capec.mitre.org/data/definitions/122.html) _(Severity: Medium)_
- [CAPEC-233 — Privilege Escalation](https://capec.mitre.org/data/definitions/233.html)

## ATT&CK-Techniken

- [T1548 — Abuse Elevation Control Mechanism](https://attack.mitre.org/techniques/T1548/)

## Referenzen

- <https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2025-042-03&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2025-042-03.pdf>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2025-0327) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
