CVE-2025-27582
7.6One Identity · Password Manager
A local privilege escalation vulnerability in the One Identity Password Manager Secure Password extension allows an attacker to gain SYSTEM privileges via a kiosk browser bypass.
Executive summary
A critical local privilege escalation flaw in One Identity Password Manager allows unauthenticated attackers with physical access to a locked workstation to gain full SYSTEM control.
Vulnerability
The vulnerability exists within the kiosk browser implementation where a flaw in the security hardening mechanism allows an unauthenticated attacker to escape the restricted environment. By navigating to a crafted webpage via the Help function, an attacker can invoke the window.print() function to trigger a system-level print dialog, ultimately spawning a command prompt with SYSTEM privileges.
Business impact
Successful exploitation grants an attacker full administrative control over the affected workstation. This poses a severe risk to organizational security, as it allows for credential theft, lateral movement within the network, and the potential deployment of persistent malicious software. Given the CVSS score of 7.6, this vulnerability represents a high-risk scenario for any environment where physical access to workstations is not strictly controlled.
Remediation
Immediate Action: Update One Identity Password Manager to version 5.14.4 or later to apply the necessary security hardening patches.
Proactive Monitoring: Monitor system logs for the unexpected execution of command prompts or print-related system dialogs originating from the Password Self-Service kiosk environment.
Compensating Controls: Restrict physical access to workstations and disable unnecessary printer-related features or shell-launching capabilities within kiosk configurations until the patch can be deployed.
Exploitation status
Public Exploit Available: Yes, a published proof-of-concept exists as documented in the research write-up by Cyberis.
Analyst recommendation
The ability for an unauthenticated user to achieve SYSTEM-level access from a locked workstation constitutes a significant security failure. Administrators must prioritize the deployment of the 5.14.4 update across all instances of the Password Manager kiosk environment. Until patching is complete, physical security measures and endpoint configuration hardening remain the primary defenses against this exploit.