CVEs (8)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Cyberark 1Endpoint Privilege Manager Feb 27, 2026 Feb 25, 2026 8.5 HIGH· v4 7.8 HIGH· v3 N/A· v2 CyberArk Endpoint Privilege Manager Agent versions 25.10.0 and lower allow potential unauthorized privilege elevation leveraging CyberArk elevation dialogs |
CyberArk Endpoint Privilege Manager Agent through 25.10.0 allows a local user to achieve privilege escalation through policy elevation of an Administration task. |
1Cyberark 1Endpoint Privilege Manager Nov 21, 2024 Jan 15, 2022 N/A· v4 7.8 HIGH· v3 6.9 MEDIUM· v2 CyberArk Endpoint Privilege Manager (EPM) through 11.5.3.328 before 2021-12-20 allows a local user to gain elevated privileges via a Trojan horse Procmon64.exe in the user's Temp directory. |
1Cyberark 1Endpoint Privilege Manager Nov 21, 2024 Nov 27, 2020 N/A· v4 5.5 MEDIUM· v3 1.9 LOW· v2 CyberArk Endpoint Privilege Manager (EPM) 11.1.0.173 allows attackers to bypass a Credential Theft protection mechanism by injecting a DLL into a process that normally has credential access, such as a Chrome process that...Show more |
1Cyberark 1Endpoint Privilege Manager Nov 21, 2024 Apr 9, 2019 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 CyberArk Endpoint Privilege Manager 10.2.1.603 and earlier allows an attacker (who is able to edit permissions of a file) to bypass intended access restrictions and execute blocked applications. |
1Cyberark 1Endpoint Privilege Manager Nov 21, 2024 Mar 8, 2019 N/A· v4 7.0 HIGH· v3 6.9 MEDIUM· v2 A buffer overflow in the kernel driver CybKernelTracker.sys in CyberArk Endpoint Privilege Manager versions prior to 10.7 allows an attacker (without Administrator privileges) to escalate privileges or crash the machine...Show more |
1Cyberark 1Endpoint Privilege Manager Nov 21, 2024 Jul 5, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In CyberArk Endpoint Privilege Manager (formerly Viewfinity), Privilege Escalation is possible if the attacker has one process that executes as Admin. |
1Cyberark 1Endpoint Privilege Manager Nov 21, 2024 Jun 26, 2018 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 In CyberArk Endpoint Privilege Manager (formerly Viewfinity) 10.2.1.603, there is persistent XSS via an account name on the create token screen, the VfManager.asmx SelectAccounts->DisplayName screen, a user's groups in C...Show more |