Beyondtrust
beyondtrust
36 CVEs • 12 products
Products (12)
Click to collapseToggle
Products (12)
Click to collapse
CVEs (36)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Beyondtrust 1Privilege Management For Windows Jun 17, 2026 Feb 16, 2024 N/A· v4 3.3 LOW· v3 N/A· v2 Prior to version 24.1, a local authenticated attacker can view Sysvol when Privilege Management for Windows is configured to use a GPO policy. This allows them to view the policy and potentially find configuration issues...Show more |
1Beyondtrust 1Privilege Management For Windows Jun 17, 2026 Dec 25, 2023 N/A· v4 6.7 MEDIUM· v3 N/A· v2 The Challenge Response feature of BeyondTrust Privilege Management for Windows (PMfW) before 2023-07-14 allows local administrators to bypass this feature by decrypting the shared key, or by locating the decrypted shared...Show more |
1Beyondtrust 1Privilege Management For Windows Jun 17, 2026 Dec 12, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 In BeyondTrust Privilege Management for Windows (aka PMfW) through 5.7, a SYSTEM installation causes Cryptbase.dll to be loaded from the user-writable location %WINDIR%\Temp. |
1Beyondtrust 1Privilege Management For Windows Jun 17, 2026 Dec 12, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 An issue was discovered in BeyondTrust Privilege Management for Windows through 5.6. If the publisher criteria is selected, it defines the name of a publisher that must be present in the certificate (and also requires th...Show more |
1Beyondtrust 1Privilege Management For Windows Jun 17, 2026 Dec 12, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 An issue was discovered in BeyondTrust Privilege Management for Windows through 5.6. When specifying a program to elevate, it can typically be found within the Program Files (x86) folder and therefore uses the %ProgramFi...Show more |
1Beyondtrust 1Privilege Management For Windows Jun 17, 2026 Dec 12, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 An issue was discovered in BeyondTrust Privilege Management for Windows through 5.6. When adding the Add Admin token to a process, and specifying that it runs at medium integrity with the user owning the process, this se...Show more |
1Beyondtrust 1Privilege Management For Mac Jun 17, 2026 Dec 11, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 An issue was discovered in BeyondTrust Privilege Management for Mac before 5.7. An authenticated, unprivileged user can elevate privileges by running a malicious script (that executes as root from a temporary directory)...Show more |
1Beyondtrust 1Privilege Management For Windows Jun 17, 2026 Dec 11, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 An issue was discovered in BeyondTrust Privilege Management for Windows through 5.6. An attacker can spawn a process with multiple users as part of the security token (prior to Avecto elevation). When Avecto elevates the...Show more |
1Beyondtrust 1Privileged Remote Access Jun 17, 2026 Oct 12, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 BeyondTrust Privileged Remote Access (PRA) versions 22.2.x to 22.4.x are vulnerable to a local authentication bypass. Attackers can exploit a flawed secret verification process in the BYOT shell jump sessions, allowing u...Show more |
1Beyondtrust 2Privileged Remote Access Remote SupportJun 17, 2026 Sep 5, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) versions 23.2.1 and 23.2.2 contain a command injection vulnerability which can be exploited through a malicious HTTP request. Successful exploitation of...Show more |
1Beyondtrust 1Appliance Base Software Jun 17, 2026 Jan 5, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A cross-site scripting (XSS) vulnerability has been reported and confirmed for BeyondTrust Secure Remote Access Base Software version 6.0.1 and older, which allows the injection of unauthenticated, specially-crafted web...Show more |
1Beyondtrust 1Privilege Management For Windows Jun 17, 2026 Nov 19, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 BeyondTrust Privilege Management prior to version 21.6 creates a Temporary File in a Directory with Insecure Permissions. |
8Beyondtrust DebianFedoraproject+5 more24Active Iq Unified Manager Cloud BackupCommunications Performance Intelligence Center+21 moreJun 17, 2026 Jan 26, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a single backslash...Show more |
1Beyondtrust 1Privilege Management For Windows And Mac Jun 17, 2026 Mar 18, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 BeyondTrust Privilege Management for Windows and Mac (aka PMWM; formerly Avecto Defendpoint) 5.1 through 5.5 before 5.5 SR1 mishandles command-line arguments with PowerShell .ps1 file extensions present, leading to a Def...Show more |
1Beyondtrust 1Avecto Defendpoint Nov 21, 2024 Apr 17, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Avecto Defendpoint 4 prior to 4.4 SR6 and 5 prior to 5.1 SR1 has an Untrusted Search Path vulnerability, exploitable by modifying environment variables to trigger automatic elevation of an attacker's process launch. |
The agent in Bomgar Remote Support 15.2.x before 15.2.3, 16.1.x before 16.1.5, and 16.2.x before 16.2.4 allows DLL hijacking because of weak %SYSTEMDRIVE%\ProgramData permissions. |