In JetBrains ReSharper, Rider and dotTrace before 2025.2.5 local privilege escalation was possible via race condition
📦
resharper
Vendor: jetbrains
Actively Exploited
0
CISA KEV List
PoC / Exploits
0
Code Available
Total RCEs
0
Remote Access
Total CVEs
8
Total Indexed
Avg. EPSS
0.17%
Exploit Prob.
Security Vulnerability Index
Page 1 / 1
4.2
CVSS
Severity: MEDIUM
8.4
CVSS
In JetBrains ReSharper before 2025.2.4 missing signature verification in DPA Collector allows local privilege escalation
Severity: HIGH
7.8
CVSS
In JetBrains ReSharper before 2024.3.4, 2024.2.8, and 2024.1.7, Rider before 2024.3.4, 2024.2.8, and 2024.1.7, dotTrace before 2024.3.4, 2024.2.8, and 2024.1.7, ETW Host Service before 16.43, Local Privilege Escalation via the ETW Host Service was possible
Severity: HIGH
7.3
CVSS
JetBrains ReSharper installers for versions before 2019.2 had a DLL Hijacking vulnerability.
Severity: HIGH