NONE · 0

CVE-2025-11535

MongoDB Connector for BI installation via MSI on Windows leaves ACLs unset on custom install directories allows Privilege Escalation.This issue affects MongoDB Connector for BI: from 2.0.0 through 2.1...

Vulnerability Description

MongoDB Connector for BI installation via MSI on Windows leaves ACLs unset on custom install directories allows Privilege Escalation.This issue affects MongoDB Connector for BI: from 2.0.0 through 2.14.24.

Related Weaknesses (CWE)

References

FAQ

What is CVE-2025-11535?

CVE-2025-11535 is a documented vulnerability. MongoDB Connector for BI installation via MSI on Windows leaves ACLs unset on custom install directories allows Privilege Escalation.This issue affects MongoDB Connector for BI: from 2.0.0 through 2.1...

How severe is CVE-2025-11535?

CVSS scoring is not yet available for CVE-2025-11535. Check NVD for updates.

Is there a patch for CVE-2025-11535?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.