CVE-2025-15319
7.8Tanium · Patch Endpoint Tools
Tanium Patch Endpoint Tools contain a local privilege escalation vulnerability caused by improper link resolution before file access.
Executive summary
A local privilege escalation vulnerability in Tanium Patch Endpoint Tools could allow a low-privileged user to gain elevated system permissions.
Vulnerability
This vulnerability is a local privilege escalation flaw classified as CWE-59: Improper Link Resolution Before File Access. An attacker with low privileges can exploit this to gain higher-level access to the host system.
Business impact
Successful exploitation allows an attacker to elevate their privileges to those of a more powerful user or system process. With a CVSS score of 7.8, this represents a high-severity risk, as it facilitates unauthorized system control, potential data theft, and the ability to disable security features on affected endpoints.
Remediation
Immediate Action: Update Tanium Patch Endpoint Tools to the latest version as specified in the vendor advisory to incorporate the necessary file access protections.
Proactive Monitoring: Monitor system logs for unauthorized attempts to access or modify sensitive files or directories associated with the Tanium agent.
Compensating Controls: Implement the principle of least privilege for local user accounts to minimize the potential impact of an escalation attempt.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the potential for full system compromise, administrators should prioritize the deployment of the provided patches across all managed endpoints. Ensure that the update cycle is completed promptly to prevent local actors from leveraging this flaw to gain elevated control over organizational infrastructure.
More Tanium CVEs
Sources
Originally found and disclosed by Owen Jeanes, per the CVE Program record.