CVE-2025-27743 is an untrusted search path vulnerability affecting multiple Microsoft System Center products, including Data Protection Manager, Operations Manager, Orchestrator, Service Manager, and Virtual Machine Manager. With a CVSS score of 7.8 (HIGH), this flaw allows an authorized local attacker to achieve privilege escalation with low attack complexity, leading to high impacts on confidentiality, integrity, and availability. While there is no public exploit code available (Metasploit, Nuclei, ExploitDB), and it is not listed in CISA's KEV catalog, community discussion and media coverage indicate some awareness, including a mention in a BleepingComputer article regarding Microsoft's April 2025 Patch Tuesday.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2019CPE matchmatch criteria | cpe:2.3:a:microsoft:system_center_data_protection_manager:2019:-:*:*:*:*:*:* | ||
2022CPE matchmatch criteria | cpe:2.3:a:microsoft:system_center_data_protection_manager:2022:-:*:*:*:*:*:* | ||
2025CPE matchmatch criteria | cpe:2.3:a:microsoft:system_center_data_protection_manager:2025:-:*:*:*:*:*:* | ||
2019CPE matchmatch criteria | cpe:2.3:a:microsoft:system_center_operations_manager:2019:-:*:*:*:*:*:* | ||
2022CPE matchmatch criteria | cpe:2.3:a:microsoft:system_center_operations_manager:2022:-:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.