CVE-2025-55077 – Tyler Technologies ERP Pro 9 SaaS Privilege Escalation Command Injection

The following table lists the changes that have been made to the
CVE-2025-55077 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by 9119a7d8-5eab-497f-8521-727c672e3725

    Aug. 07, 2025

    Action Type Old Value New Value
    Added Description Tyler Technologies ERP Pro 9 SaaS allows an authenticated user to escape the application and execute limited operating system commands within the remote Microsoft Windows environment with the privileges of the authenticated user. Tyler Technologies deployed hardened remote Windows environment settings to all ERP Pro 9 SaaS customer environments as of 2025-08-01.
    Added CVSS V4.0 AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
    Added CVSS V3.1 AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L
    Added CWE CWE-668
    Added CWE CWE-250
    Added CWE CWE-863
    Added Reference https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-219-01.json
    Added Reference https://www.cve.org/CVERecord?id=CVE-2025-55077
Share the Post:

Related Posts