CVE-2025-4235

User-ID Credential Agent: Cleartext Exposure of Service Account password

Severity
High 7.2
CVSS 4.0
Adjacent, local or physical access what this means
Exploited
Not listed
EPSS
0.002
6.8th percentile
Discovered by
Third party
Vendor-published field
Published
Sep 12, 2025
Assigned by palo_alto

Description

An information exposure vulnerability in the Palo Alto Networks User-ID Credential Agent (Windows-based) can expose the service account password under specific non-default configurations. This allows an unprivileged Domain User to escalate privileges by exploiting the account’s permissions. The impact varies by configuration: * Minimally Privileged Accounts: Enable disruption of User-ID Credential Agent operations (e.g., uninstalling or disabling the agent service), weakening network security policies that leverage Credential Phishing Prevention https://docs.paloaltonetworks.com/advanced-url-filtering/administration/url-filtering-features/credential-phishing-prevention under a Domain Credential Filter https://docs.paloaltonetworks.com/advanced-url-filtering/administration/url-filtering-features/credential-phishing-prevention/methods-to-check-for-corporate-credential-submissions configuration. * Elevated Accounts (Server Operator, Domain Join, Legacy Features): Permit increased impacts, including server control (e.g., shutdown/restart), domain manipulation (e.g., rogue computer objects), and network compromise via reconnaissance or client probing.

Weakness: CWE-497

Affected products

Vendor Product Category Matched by
Palo Alto Networks User-ID Agent Identity / IAM / MFA cna-assigner
Vendor-reported products (1)
  • Palo Alto Networks · User-ID Credential Agent — vendor states not affected

Credit

Palo Alto Networks thanks an external reporter for discovering and reporting this issue.

Vendor remediation

Version Minor Version Suggested Solution User-ID Credential Agent 11.0 on Windows 11.0.2-133Upgrade to 11.0.3 or later 11.0.0 through 11.0.1-104No action needed.

Something wrong here?