CVE-2025-6250 Details
Description
Prior to 25.4.270.0, when wmic.exe is elevated with a full admin token the user can stop the Defendpoint service, bypassing anti-tamper protections. Once the service is disabled, the malicious user can add themselves to Administrators group and run any process with elevated permissions.
A vulnerability exists in BeyondTrust Privilege Management for Windows, prior to version 25.4.270.0, allowing a local authenticated attacker with elevated privileges to bypass anti-tamper protections. By using an elevated wmic.exe with a full admin token, the attacker can stop the Defendpoint service. Once the service is disabled, the attacker can add themselves to the Administrators group and execute any process with elevated permissions.
Users can upgrade to BeyondTrust Privilege Management for Windows version 25.4.270.0 or later. For versions prior to 25.4.270.0, a rule can be created to block wmic.exe execution completely or allow gated or limited access. Instructions for creating these rules are available in the BeyondTrust knowledge base.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 28, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.beyondtrust.com/trust-center/security-advisories/bt25-06 | BeyondTrust | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-424 | Improper Protection of Alternate Path | BeyondTrust |
Affected Products
| Product | Versions |
|---|---|
| beyondtrust privilege management for windows | < 25.4.270 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | BeyondTrust |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Aug 4, 2025 | Initial Analysis | [email protected] |
| Jul 28, 2025 | New CVE Received | BeyondTrust |