CVE-2025-40672 – ProactivaNet from Grupo Espiral MS Privilege Escalation Vulnerability

The following table lists the changes that have been made to the
CVE-2025-40672 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by [email protected]

    May. 26, 2025

    Action Type Old Value New Value
    Added Description A Privilege Escalation vulnerability has been found in ProactivaNet v3.24.0.0 from Grupo Espiral MS. This vulnerability allows any user to override the file panLoad.exe that will be executed by SYSTEM user via a programmed task.
    This would allow an attacker to obtain administrator permissions to
    perform whatever activities he/she wants, shuch as accessing sensitive
    information, executing code remotely, and even causing a denial of
    service (DoS).
    Added CVSS V4.0 AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
    Added CWE CWE-732
    Added Reference https://www.incibe.es/en/incibe-cert/notices/aviso/privilege-escalation-proactivanet-espiral-ms-group
Share the Post:

Related Posts