Skip to main content
Vulnerability Database/CVE-2025-66374

CVE-2025-66374: CyberArk EPM Privilege Escalation Flaw

CVE-2025-66374 is a privilege escalation vulnerability in CyberArk Endpoint Privilege Manager Agent (through 25.10.0) that enables local users to elevate privileges via policy manipulation. This article covers technical details, affected versions, security impact, and recommended mitigation strategies.

Updated:

CVE-2025-66374 Overview

CVE-2025-66374 affects CyberArk Endpoint Privilege Manager (EPM) Agent through version 25.10.0 on Windows. A local user can achieve privilege escalation by abusing policy elevation of an Administration task. The flaw maps to [CWE-269: Improper Privilege Management] and carries a CVSS 3.1 base score of 7.8.

CyberArk assigned the issue advisory identifier CA26-01 and addressed it in EPM version 25.12. The vulnerability is significant because EPM is deployed specifically to enforce least-privilege policies on Windows endpoints, so a bypass undermines the primary control the product provides.

Critical Impact

An authenticated local user on a Windows endpoint running the vulnerable EPM Agent can escalate to elevated privileges through an Administration task governed by an elevation policy, compromising confidentiality, integrity, and availability of the host.

Affected Products

  • CyberArk Endpoint Privilege Manager Agent for Windows, all versions up to and including 25.10.0
  • Deployments relying on EPM elevation policies for Administration tasks
  • Endpoints where standard users are governed by EPM rather than direct local admin membership

Discovery Timeline

  • 2026-02-03 - CVE-2025-66374 published to the National Vulnerability Database
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2025-66374

Vulnerability Analysis

CyberArk Endpoint Privilege Manager brokers privilege elevation for defined applications and administrative tasks on Windows. Elevation policies allow standard users to perform specific privileged operations without receiving full local administrator rights. CVE-2025-66374 is a local privilege escalation flaw in how the EPM Agent handles the elevation of an Administration task.

The vulnerability sits in the trust boundary between a low-privilege user session and the elevated context that the agent grants to a policy-approved task. A local user who is already authorized to trigger the affected Administration task can leverage the elevation mechanism to obtain privileges beyond what the policy intends to grant. Successful exploitation yields high impact to confidentiality, integrity, and availability on the affected host.

Because exploitation is local and requires low privileges with no user interaction, an attacker who has already gained an initial foothold on a Windows endpoint can chain this issue to move from standard user to administrative control. CyberArk has not released public technical details of the underlying defect beyond the advisory reference.

Root Cause

The root cause is improper privilege management ([CWE-269]) in the EPM Agent's handling of an Administration task subject to a policy-driven elevation. The agent grants elevated context in a way that the local user can influence or repurpose, resulting in privileges broader than the policy defines. CyberArk's remediation notes address the issue in the 25.12 release, indicating a change in how the agent validates or scopes the elevated task.

Attack Vector

The attack vector is local. The attacker must already be authenticated on the Windows endpoint with low privileges and must be within scope of an EPM elevation policy that covers the vulnerable Administration task. No user interaction from another account is required. Refer to the CyberArk Security Advisory CA26-01 and the CyberArk Release Notes Update for vendor-provided technical context. No public proof-of-concept exploit code is available at the time of publication.

Detection Methods for CVE-2025-66374

Indicators of Compromise

  • Unexpected child processes spawned from EPM Agent components running under NT AUTHORITY\SYSTEM or elevated administrator tokens on hosts where the initiating user is a standard account.
  • EPM audit events showing elevation of Administration tasks followed by process launches, token manipulation, or privileged file and registry writes outside the scope of the approved task.
  • Standard user accounts creating or modifying services, scheduled tasks, or entries under HKLM\SOFTWARE shortly after an EPM elevation event.

Detection Strategies

  • Correlate EPM policy elevation events with subsequent Windows Security event IDs 4688 (process creation) and 4672 (special privileges assigned) to identify elevation chains that exceed policy intent.
  • Hunt for processes launched with elevated integrity levels whose parent is an EPM Agent binary but whose command line or image path is not part of a sanctioned Administration task.
  • Baseline the set of Administration tasks approved by policy per user group and alert on deviations, especially repeated elevation attempts from the same low-privilege account.

Monitoring Recommendations

  • Forward EPM Agent audit logs and Windows Security, Sysmon, and PowerShell operational logs to a centralized analytics platform for cross-source correlation.
  • Monitor version telemetry across managed endpoints to confirm agents are upgraded to 25.12 or later and flag hosts still reporting 25.10.0 or earlier.
  • Track privileged local group membership changes and new local account creation events on endpoints that host the EPM Agent.

How to Mitigate CVE-2025-66374

Immediate Actions Required

  • Upgrade the CyberArk EPM Agent on all Windows endpoints to version 25.12 or later as documented in the vendor release notes.
  • Inventory endpoints still running EPM Agent 25.10.0 or earlier and prioritize patching for systems accessible to interactive users.
  • Review EPM elevation policies covering Administration tasks and tighten scope to the minimum set of users and applications required.

Patch Information

CyberArk addressed CVE-2025-66374 in EPM version 25.12. See the CyberArk Release Notes Update, the CyberArk Security Advisory CA26-01, and the CyberArk Product Security Information page for release artifacts and additional guidance. Deploy the update through the standard EPM Management Console update workflow and confirm agent version reporting after rollout.

Workarounds

  • Temporarily disable or restrict the elevation policies covering the affected Administration tasks until agents are updated.
  • Limit interactive logon on high-value endpoints to reduce the population of local users who could reach the vulnerable code path.
  • Enforce application control and Windows Defender Application Control or AppLocker rules to constrain what elevated processes can execute during the exposure window.
bash
# Example: query installed EPM Agent version on a Windows endpoint via PowerShell
Get-CimInstance -ClassName Win32_Product |
  Where-Object { $_.Name -like 'CyberArk Endpoint Privilege Manager*' } |
  Select-Object Name, Version, Vendor

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.