CVE-2025-1755

M

ongoDB Compass may be susceptible to local privilege escalation under certain conditions potentially enabling unauthorized actions on a user's system with elevated privileges, when a crafted file is stored in C:\node_modules\. This issue affects MongoDB Compass prior to 1.42.1

References
Link Resource
https://jira.mongodb.org/browse/COMPASS-9058 Vendor Advisory Issue Tracking
https://access.redhat.com/errata/RHSA-2025:1755.html Third Party Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:mongodb:compass:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:redhat:enterprise_linux_for_arm_64:9.0_aarch64:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems:9.0_s390x:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions:9.0_ppc64le:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_update_services_for_sap_solutions:9.0:*:*:*:*:*:*:*

History

09 Apr 2025, 14:07

Type Values Removed Values Added
First Time Mongodb compass
Microsoft
Redhat enterprise Linux Server For Power Little Endian Update Services For Sap Solutions
Mongodb
Redhat
Redhat enterprise Linux For Arm 64
Redhat enterprise Linux For Ibm Z Systems
Redhat enterprise Linux Update Services For Sap Solutions
Microsoft windows
CPE cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:*:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions:9.0_ppc64le:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_update_services_for_sap_solutions:9.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_for_arm_64:9.0_aarch64:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems:9.0_s390x:*:*:*:*:*:*:*
References () https://jira.mongodb.org/browse/COMPASS-9058 - () https://jira.mongodb.org/browse/COMPASS-9058 - Vendor Advisory, Issue Tracking
References () https://access.redhat.com/errata/RHSA-2025:1755.html - () https://access.redhat.com/errata/RHSA-2025:1755.html - Third Party Advisory
Summary
  • (es) MongoDB Compass puede ser susceptible a una escalada de privilegios locales en determinadas condiciones, lo que podría permitir acciones no autorizadas en el sistema de un usuario con privilegios elevados, cuando un archivo manipulado se almacena en C:\node_modules\. Este problema afecta a MongoDB Compass anterior a la versión 1.42.1.

27 Feb 2025, 16:15

Type Values Removed Values Added
New CVE