CVE-2025-15310 Details
Description
Tanium addressed a local privilege escalation vulnerability in Patch Endpoint Tools.
A local privilege escalation vulnerability has been identified in Tanium Patch Endpoint Tools versions 3.17 prior to 3.17.10195, 10.1 prior to 10.1.33, and 10.2 prior to 10.2.22. This vulnerability allows an attacker with access to a system running the Tanium Client to escalate privileges locally by manipulating files in user-controlled locations.
Users should upgrade to Tanium Patch version 3.17.2261 or later, or to Tanium Endpoint Configuration Toolset Solution version 1.40.37 or later. Tanium on-prem customers on SARH1 should deploy Manifest version 2.2.112 and later to all endpoints. Those on SARH2 should deploy Manifest version 2.9.16 and later. Tanium Cloud customers using ECM should deploy either Manifest version 2.10.19 and later or version 2.7.56 and later to all endpoints.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 10, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://security.tanium.com/TAN-2025-001 | Tanium | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
| CWE-59 | Improper Link Resolution Before File Access ('Link Following') | Tanium |
Affected Products
| Product | Versions |
|---|---|
| tanium endpoint configuration toolset solution | < 1.40.37 |
CPE
Remediation
| |
| tanium patch endpoint tools | >= 3.17, < 3.17.10195 >= 10.1, < 10.1.33 >= 10.2, < 10.2.22 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | Tanium |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 24, 2026 | Initial Analysis | [email protected] |
| Feb 10, 2026 | New CVE Received | Tanium |