CVE-2025-15554: medium-severity vulnerability in Truesec LAPSWebUI
Admin Passwords Cached by Browsers in Truesec LAPSWebUI
Published
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 6epss 0.1%
exploitation probability
0.1%top 97% of all CVEs
observed exploitation
nono source reports it
Browser caching of LAPS passwords in Truesec’s LAPSWebUI before version 2.4 allows an attacker with access to a workstation to escalate their privileges via disclosure of local admin passwords.
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H
Affected products
Truesec · LAPSWebUIRelated CVEs — Truesec LAPSWebUI
In the same product, most dangerous first.