Search/CVE-2025-23385
CVE — High

CVE-2025-23385

In JetBrains ReSharper before 2024.3.4, 2024.2.8, and 2024.1.7, Rider before 2024.3.4, 2024.2.8, and 2024.1.7, dotTrace before 2024.3.4, 2024.2.8, and 2024.1.7, ETW Host Service before 16.43, Local Privilege Escalation via the ETW Host Service was possible

CVSS v3.1
7.8 HIGH
EPSS
0.14%
probability of exploitation in 30 days
CISA KEV
Not listed
no confirmed exploitation reported
News coverage
0
sources referencing this CVE
EPSS Trend
Aug 16, 2026Aug 24, 2026
0.00pp
0.13% → 0.14% over 2 tracked changes
CVSS v3.1 Detail
Attack VectorLOCAL
Attack ComplexityHIGH
Privileges RequiredLOW
User InteractionNONE
ScopeCHANGED
ConfidentialityHIGH
IntegrityHIGH
AvailabilityHIGH
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
Connections
5 relationships
Timeline
disclosure → media coverage
Jan 28, 2025
Disclosure — published as a CVE record. · last revised by NVD Jan 12, 2026