
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-64457 is a local privilege escalation vulnerability affecting JetBrains ReSharper, Rider, and dotTrace before version 2025.2.5, caused by a time-of-check time-of-use (TOCTOU) race condition. It was published on November 10, 2025, with a patch available in version 2025.2.5. The vulnerability carries a CVSS v3.1 base score of 7.0 (High) (JetBrains Security, Red Hat Advisory).
The vulnerability is classified under CWE-367 (Time-of-Check Time-of-Use Race Condition) and CWE-362 (Concurrent Execution using Shared Resource with Improper Synchronization). An attacker with low-level local privileges can exploit a timing window during the software's execution — between the time a resource is checked and the time it is used — to manipulate the resource and escalate privileges. The attack vector is local, requires no user interaction, but has high attack complexity due to the precise timing required to win the race condition. No public proof-of-concept code has been identified (JetBrains Security, Red Hat Advisory).
Successful exploitation allows an authenticated local attacker to gain elevated privileges on the affected system, resulting in high confidentiality, integrity, and availability impact. This could enable unauthorized access to sensitive data, modification of system files or configurations, and disruption of services. The risk is most pronounced in multi-user or shared development environments where multiple users have local access to systems running the affected JetBrains tools (Red Hat Advisory).
There is no evidence of active in-the-wild exploitation or a publicly available proof-of-concept at this time. The EPSS score is extremely low at 0.00001, reflecting minimal current exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. A patch has been released by JetBrains in version 2025.2.5 (JetBrains Security, Red Hat Advisory).
JetBrains has released version 2025.2.5 of ReSharper, Rider, and dotTrace to address this vulnerability. Users should immediately update all affected products to version 2025.2.5 or later. As additional hardening measures, administrators should restrict local access to systems running these tools, implement proper authentication controls, and monitor for suspicious privilege escalation activity in development environments (JetBrains Security, JetBrains Blog).
JetBrains published a blog post on December 18, 2025 covering the ReSharper and Rider 2025.3.1 release, which references the security fixes. Red Hat also published a security advisory for this CVE. No significant independent researcher commentary or notable media coverage has been identified beyond standard vulnerability database entries (JetBrains Blog, Red Hat Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."