CVE-2025-0712 – Apache HTTP Server Unauthenticated Local Privilege Escalation

The following table lists the changes that have been made to the
CVE-2025-0712 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by [email protected]

    Jul. 30, 2025

    Action Type Old Value New Value
    Added Description An uncontrolled search path element vulnerability can lead to local privilege Escalation (LPE) via Insecure Directory Permissions. The vulnerability arises from improper handling of directory permissions. An attacker with local access may exploit this flaw to move and delete arbitrary files, potentially gaining SYSTEM privileges.
    Added CVSS V3.1 AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
    Added CWE CWE-427
    Added Reference https://discuss.elastic.co/t/beats-windows-installer-9-1-0-security-update-esa-2025-12/380558
Share the Post:

Related Posts