CVE-2025-55077 Details
Description
Tyler Technologies ERP Pro 9 SaaS allows an authenticated user to escape the application and execute limited operating system commands within the remote Microsoft Windows environment with the privileges of the authenticated user. Tyler Technologies deployed hardened remote Windows environment settings to all ERP Pro 9 SaaS customer environments as of 2025-08-01.
A vulnerability in Tyler Technologies ERP Pro 9 SaaS allows authenticated users to escape the application environment and execute limited operating system commands in the remote Microsoft Windows environment. This execution occurs with the privileges of the authenticated user. As of August 1, 2025, Tyler Technologies has implemented enhanced security settings in the Windows environment for all ERP Pro 9 SaaS customers.
Tyler Technologies has deployed hardened remote Windows environment settings to all ERP Pro 9 SaaS customer environments as of August 1, 2025.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Aug 12, 2025CISA-ADP
Assessed Aug 7, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-219-01.json | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government | Third Party Advisory |
| https://www.cve.org/CVERecord?id=CVE-2025-55077 | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
| CWE-250 | Execution with Unnecessary Privileges | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government |
| CWE-668 | Exposure of Resource to Wrong Sphere | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government |
| CWE-863 | Incorrect Authorization | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government |
Affected Products
| Product | Versions |
|---|---|
| tylertech erp pro 9 | 2025-08-01 |
CPE
Remediation
| |
| microsoft windows | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Sep 23, 2025 | Initial Analysis | [email protected] |
| Aug 7, 2025 | New CVE Received | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government |