CVE 8.5 HIGH

Root Certificate Injection_CVE-2025-6182

8.5 / 10
HIGH
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Description

The StrongDM Windows service incorrectly handled communication related to system certificate management. Attackers could exploit this behavior to install untrusted root certificates or remove trusted ones.

Basic Information

ID CVE-2025-6182
Source StrongDM
Published Aug 20, 2025 at 16:44
Modified Aug 20, 2025 at 17:39

Affected Product

Vendor StrongDM
Product sdm
Affected Versions StrongDM sdm 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.