
CVE-2025-32714 – Windows Installer Elevation of Privilege Vulnerability
https://notcve.org/view.php?id=CVE-2025-32714
10 Jun 2025 — Improper access control in Windows Installer allows an authorized attacker to elevate privileges locally. This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. ... An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-32714 • CWE-284: Improper Access Control •

CVE-2025-33075 – Windows Installer Elevation of Privilege Vulnerability
https://notcve.org/view.php?id=CVE-2025-33075
10 Jun 2025 — Improper link resolution before file access ('link following') in Windows Installer allows an authorized attacker to elevate privileges locally. This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. ... An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-33075 • CWE-59: Improper Link Resolution Before File Access ('Link Following') •

CVE-2025-45055
https://notcve.org/view.php?id=CVE-2025-45055
09 Jun 2025 — This allows attackers to escalate privileges by creating a new administrator account. • https://github.com/Silverpeas/Silverpeas-Core/pull/1394 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2025-29627
https://notcve.org/view.php?id=CVE-2025-29627
09 Jun 2025 — An issue in KeeperChat IOS Application v.5.8.8 allows a physically proximate attacker to escalate privileges via the Biometric Authentication Module • https://github.com/SahilDabhilkar/CVE-Reference/blob/main/CVE-2025-29627.md • CWE-287: Improper Authentication •

CVE-2025-43026 – HP Support Assistant – Potential Escalation of Privilege
https://notcve.org/view.php?id=CVE-2025-43026
05 Jun 2025 — The vulnerability could potentially allow a local attacker to escalate privileges via an arbitrary file write. • https://support.hp.com/us-en/document/ish_12617979-12618008-16/hpsbgn04022 • CWE-281: Improper Preservation of Permissions •

CVE-2025-48961
https://notcve.org/view.php?id=CVE-2025-48961
04 Jun 2025 — Local privilege escalation due to insecure folder permissions. • https://security-advisory.acronis.com/advisories/SEC-8000 • CWE-732: Incorrect Permission Assignment for Critical Resource •

CVE-2025-1701 – Local Privilege Escalation in MIM Admin Service
https://notcve.org/view.php?id=CVE-2025-1701
04 Jun 2025 — An attacker could exploit this vulnerability by sending a specially crafted request over the RMI interface to execute arbitrary code with the privileges of the MIM Admin service. ... From there, attackers with sufficient knowledge of MIM's implementation, library usage, and functionality with access to extend the MIM RMI library could force the MIM Admin service to run commands on the local machine with its privileges. • https://www.mimsoftware.com/cve-2025-1701 • CWE-20: Improper Input Validation CWE-306: Missing Authentication for Critical Function •

CVE-2025-48959
https://notcve.org/view.php?id=CVE-2025-48959
04 Jun 2025 — Local privilege escalation due to insecure file permissions. • https://security-advisory.acronis.com/advisories/SEC-8133 • CWE-276: Incorrect Default Permissions •

CVE-2024-31127 – MacOS Zscaler Client Connector Local Privilege Escalation
https://notcve.org/view.php?id=CVE-2024-31127
04 Jun 2025 — An improper verification of a loaded library in Zscaler Client Connector on Mac < 4.2.0.241 may allow a local attacker to elevate their privileges. • https://help.zscaler.com/zscaler-client-connector/client-connector-app-release-summary-2023?applicable_category=macOS&applicable_version=4.2&deployment_date=2023-12-14 • CWE-346: Origin Validation Error •

CVE-2025-27811
https://notcve.org/view.php?id=CVE-2025-27811
04 Jun 2025 — A local privilege escalation in the razer_elevation_service.exe in Razer Synapse 4 through 4.0.86.2502180127 allows a local attacker to escalate their privileges via a vulnerable COM interface in the target service. • https://app.inspectiv.com/#/submissions/EAEDG9ssRaTWKSJJ5Bbrt9 • CWE-269: Improper Privilege Management •