CVE-2025-27703 – Absolute Secure Access Privilege Escalation Vulnerability

The following table lists the changes that have been made to the
CVE-2025-27703 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by [email protected]

    May. 28, 2025

    Action Type Old Value New Value
    Added Description CVE-2025-27703 is a privilege escalation vulnerability in the management
    console of Absolute Secure Access prior to version 13.54. Attackers
    with administrative access to a specific subset of privileged features
    in the console can elevate their permissions to access additional
    features in the console. The attack complexity is low, there are no
    preexisting attack requirements; the privileges required are high, and
    there is no user interaction required. The impact to system
    confidentiality is low, the impact to system integrity is high and the
    impact to system availability is low.
    Added CVSS V4.0 AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
    Added Reference https://www.absolute.com/platform/vulnerability-archive/cve-2025-27703
Share the Post:

Related Posts