The Challenge Response feature of BeyondTrust Privilege Management for Windows (PMfW) before 2023-07-14 allows local administrators to bypass this feature by decrypting the shared key, or by locating the decrypted shared key in process memory. The threat is mitigated by the Agent Protection feature.
References
Link | Resource |
---|---|
https://www.beyondtrust.com/security | Vendor Advisory |
https://www.beyondtrust.com/trust-center/security-advisories/bt23-08 | Vendor Advisory |
Configurations
History
03 Jan 2024, 22:53
Type | Values Removed | Values Added |
---|---|---|
CWE | NVD-CWE-noinfo | |
References | () https://www.beyondtrust.com/trust-center/security-advisories/bt23-08 - Vendor Advisory | |
References | () https://www.beyondtrust.com/security - Vendor Advisory | |
CPE | cpe:2.3:a:beyondtrust:privilege_management_for_windows:*:*:*:*:*:*:*:* | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.7 |
First Time |
Beyondtrust privilege Management For Windows
Beyondtrust |
25 Dec 2023, 08:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-12-25 08:15
Updated : 2024-02-28 20:54
NVD link : CVE-2023-49944
Mitre link : CVE-2023-49944
CVE.ORG link : CVE-2023-49944
JSON object : View
Products Affected
beyondtrust
- privilege_management_for_windows
CWE