CVE-2025-41686

7.8

Phoenix Contact · DaUM

A privilege escalation vulnerability exists in the nssm.exe component of Phoenix Contact DaUM, allowing local attackers to gain administrative access due to improper permissions.

Executive summary

A high-severity local privilege escalation vulnerability in Phoenix Contact DaUM allows low-privileged users to achieve administrative control over the system.

Vulnerability

The flaw is a missing authentication for a critical function (CWE-306) residing within the nssm.exe service manager. A local attacker with low privileges can exploit these improper permissions to execute commands with elevated administrative rights.

Business impact

The vulnerability carries a CVSS score of 7.8, indicating a high level of risk for organizations utilizing this software. Successful exploitation allows an attacker to bypass standard security boundaries, potentially leading to full system compromise, unauthorized data access, and the ability to install malicious software or modify critical configurations.

Remediation

Immediate Action: Update Phoenix Contact DaUM to version 2025.3.1 or later to resolve the improper permission configuration in the nssm.exe component.

Proactive Monitoring: Audit local system logs for unauthorized service modifications or unexpected execution of administrative tasks by low-privileged user accounts.

Compensating Controls: Implement strict principle of least privilege policies on local Windows systems to restrict the ability of standard users to interact with service executables and modify their associated file permissions.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the severity of potential privilege escalation, organizations must prioritize the deployment of the vendor-supplied update across all affected DaUM installations. Administrators should verify the patch version 2025.3.1 is applied immediately to eliminate the underlying permission flaw and prevent unauthorized administrative access.

More Phoenix Contact CVEs

Sources