CVE-2025-53819
Raw vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:LSummary
CVE-2025-53819 is a high-severity Privilege Dropping / Lowering Errors (CWE-271) vulnerability. Its CVSS base score is 7.9 (High).
Operationally, exploitation aligns with the MITRE ATT&CK technique Setuid and Setgid (T1548.001); ranked at the 3th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.
The strongest mitigations our analysis identified map to AC-6 (Least Privilege) and AC-3 (Access Enforcement) — see the control section below for these in your framework.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2025-21392
Vulnerability Data
Nix is a package manager for Linux and other Unix systems. Builds with Nix 2.30.0 on macOS were executed with elevated privileges (root), instead of the build users. The fix was applied to Nix 2.30.1. No known workarounds are available.
- CWE(s)
Related Threats
MITRE ATT&CK Enterprise Techniques
CVEs Like This One
Affected Assets
Mitigating Controls
Mitigating Controls (NIST 800-53 r5) AI
Least privilege explicitly mandates dropping privileges to the minimum necessary before transferring control.
Access enforcement directly requires that privileges are lowered before handing resources to less-privileged actors.
Mitigating Controls (NIST CSF 2.0) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.
Explicit inclusion of least-privilege policy directly addresses failure to drop privileges before handing control to lower-privileged actors.
Secure-development practices encompass correct privilege-dropping logic, though the control is broader than this single weakness.
Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.
Restricting use of privileged utility programs forces explicit privilege lowering before handing control to unprivileged actors.
Privileged access rights explicitly require least-privilege assignment and timely revocation, directly mitigating failure to drop privileges.
Secure development lifecycle includes privilege management reviews, providing indirect coverage of the weakness.
Secure coding standards can mandate privilege-dropping calls, yet the control is broader than this single weakness.
Information access restriction policies can limit privilege scope but do not specifically address dropping privileges at runtime.