ICS: Multiple Siemens TeleControl Server Vulnerabilities
April 17, 2025Multiple WordPress Plugins Vulnerabilities
April 17, 2025ICS: Multiple Siemens TeleControl Server Vulnerabilities
April 17, 2025Multiple WordPress Plugins Vulnerabilities
April 17, 2025Severity
High
Analysis Summary
CVE-2025-29801 CVSS:7.8
Incorrect default permissions in Microsoft AutoUpdate (MAU) allows an authorized attacker to elevate privileges locally.
CVE-2025-29800 CVSS:7.8
Improper privilege management in Microsoft AutoUpdate (MAU) allows an authorized attacker to elevate privileges locally.
Impact
- Privilege Escalation
Indicators of Compromise
CVE
CVE-2025-29801
CVE-2025-29800
Affected Vendors
- Microsoft
Affected Products
- Microsoft AutoUpdate for Mac
Remediation
Use Microsoft Automatic Update to apply the appropriate patch for your system, or the Microsoft Security Update Guide to search for available patches.