CVE-2025-64456
8.4JetBrains · ReSharper
JetBrains ReSharper versions prior to 2025.2.4 are vulnerable to a local privilege escalation due to missing signature verification in the DPA Collector.
Executive summary
A missing signature verification flaw in the JetBrains ReSharper DPA Collector allows a local attacker to achieve privilege escalation, posing a high risk to system integrity.
Vulnerability
The vulnerability involves a lack of signature verification within the DPA Collector component, which is classified as CWE-347. This flaw enables an attacker with local, low-privileged access to escalate their privileges within the host environment.
Business impact
The ability for a local user to escalate privileges creates a significant security risk, as it allows unauthorized access to sensitive system resources and administrative functions. Given the CVSS score of 8.4, this vulnerability is considered High, as it could lead to full system compromise if exploited by a malicious actor already present on the local machine.
Remediation
Immediate Action: Update JetBrains ReSharper to version 2025.2.4 or later immediately to resolve the signature verification flaw.
Proactive Monitoring: Review system and application logs for unexpected DPA Collector process behavior or unauthorized execution attempts by low-privileged user accounts.
Compensating Controls: Restrict local access to the affected machine to authorized personnel only, and implement endpoint detection and response tools to identify anomalous privilege escalation patterns.
Exploitation status
Public Exploit Available: No
Analyst recommendation
This vulnerability presents a clear path for local privilege escalation and warrants immediate attention. Organizations should prioritize updating all instances of JetBrains ReSharper to the patched version, 2025.2.4, to eliminate the exposure. Delaying this update risks allowing local attackers to gain elevated control over development workstations or server environments where ReSharper is deployed.