CVE-2025-23385 Details
Description
In JetBrains ReSharper before 2024.3.4, 2024.2.8, and 2024.1.7, Rider before 2024.3.4, 2024.2.8, and 2024.1.7, dotTrace before 2024.3.4, 2024.2.8, and 2024.1.7, ETW Host Service before 16.43, Local Privilege Escalation via the ETW Host Service was possible
A local privilege escalation vulnerability has been identified in multiple JetBrains products, including ReSharper, Rider, dotTrace, and the ETW Host Service. This vulnerability exists in specific versions of these products and allows unauthorized users to escalate privileges by exploiting the ETW Host Service.
Users can update to the latest versions of the affected JetBrains products to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jan 28, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.jetbrains.com/privacy-security/issues-fixed/ | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
| CWE-114 | Process Control | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| jetbrains dottrace | < 2024.1.7 >= 2024.2, < 2024.2.8 >= 2024.3, < 2024.3.4 |
CPE
Remediation
| |
| jetbrains etw host service | < 16.43 |
CPE
Remediation
| |
| jetbrains resharper | < 2024.1.7 >= 2024.2, < 2024.2.8 >= 2024.3, < 2024.3.4 |
CPE
Remediation
| |
| jetbrains rider | < 2024.1.7 >= 2024.2.0, < 2024.2.8 >= 2024.3.0, < 2024.3.4 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 12, 2026 | Initial Analysis | [email protected] |
| Jan 28, 2025 | New CVE Received | [email protected] |