CVE-2025-55077 describes a vulnerability in Tyler Technologies ERP Pro 9 SaaS where an authenticated user can escape the application and execute limited operating system commands on the remote Microsoft Windows environment with their own privileges. This high-severity vulnerability (CVSS 7.4) has a low attack complexity and could lead to limited confidentiality, integrity, and availability impacts. While no active exploitation, public exploit code, or significant community discussion has been observed, Tyler Technologies has deployed hardened remote Windows environment settings to all affected SaaS customer environments as of August 1, 2025.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2025-08-01CPE matchmatch criteria | cpe:2.3:a:tylertech:erp_pro_9:2025-08-01:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.