Beyondtrust
Beyondtrust Privilege Management FOR Windows: vulnerabilidades y CVE
Beyondtrust Privilege Management FOR Windows tiene 13 vulnerabilidades publicadas, 1 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE13
Últimos 12 meses1
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-1232 | Media (6.8) | 0.14% | — | 2 feb 2026 | A medium-severity vulnerability has been identified in BeyondTrust Privilege Management for Windows versions <=25.7. Under certain conditions, a local authenticated user with elevated privileges may be able to bypass… |
| CVE-2025-6250 | Alta (7.1) | 0.16% | — | 28 jul 2025 | Prior to 25.4.270.0, when wmic.exe is elevated with a full admin token the user can stop the Defendpoint service, bypassing anti-tamper protections. Once the service is disabled, the malicious user can add themselves to… |
| CVE-2025-2297 | Alta (7.2) | 0.13% | — | 28 jul 2025 | Prior to version 25.4.270.0, a local authenticated attacker can manipulate user profile files to add illegitimate challenge response codes into the local user registry under certain conditions. This allows users with… |
| CVE-2025-0889 | Alta (7.2) | 0.20% | — | 26 feb 2025 | Prior to 25.2, a local authenticated attacker can elevate privileges on a system with Privilege Management for Windows installed, via the manipulation of COM objects under certain circumstances where an EPM policy… |
| CVE-2024-25083 | Alta (7.8) | 0.13% | — | 16 feb 2024 | An issue was discovered in BeyondTrust Privilege Management for Windows before 24.1. When an low-privileged user initiates a repair, there is an attack vector through which the user is able to execute any program with… |
| CVE-2024-1591 | Baja (3.3) | 0.16% | — | 16 feb 2024 | Prior to version 24.1, a local authenticated attacker can view Sysvol when Privilege Management for Windows is configured to use a GPO policy. This allows them to view the policy and potentially find configuration… |
| CVE-2023-49944 | Media (6.7) | 0.18% | — | 25 dic 2023 | The Challenge Response feature of BeyondTrust Privilege Management for Windows (PMfW) before 2023-07-14 allows local administrators to bypass this feature by decrypting the shared key, or by locating the decrypted… |
| CVE-2020-28369 | Alta (7.8) | 0.23% | — | 12 dic 2023 | In BeyondTrust Privilege Management for Windows (aka PMfW) through 5.7, a SYSTEM installation causes Cryptbase.dll to be loaded from the user-writable location %WINDIR%\Temp. |
| CVE-2020-12614 | Alta (7.8) | 0.14% | — | 12 dic 2023 | An issue was discovered in BeyondTrust Privilege Management for Windows through 5.6. If the publisher criteria is selected, it defines the name of a publisher that must be present in the certificate (and also requires… |
| CVE-2020-12612 | Alta (7.8) | 0.26% | — | 12 dic 2023 | An issue was discovered in BeyondTrust Privilege Management for Windows through 5.6. When specifying a program to elevate, it can typically be found within the Program Files (x86) folder and therefore uses the… |
| CVE-2020-12615 | Alta (7.8) | 0.22% | — | 12 dic 2023 | An issue was discovered in BeyondTrust Privilege Management for Windows through 5.6. When adding the Add Admin token to a process, and specifying that it runs at medium integrity with the user owning the process, this… |
| CVE-2020-12613 | Alta (8.8) | 0.77% | — | 11 dic 2023 | An issue was discovered in BeyondTrust Privilege Management for Windows through 5.6. An attacker can spawn a process with multiple users as part of the security token (prior to Avecto elevation). When Avecto elevates… |
| CVE-2021-42254 | Alta (7.8) | 0.30% | — | 19 nov 2021 | BeyondTrust Privilege Management prior to version 21.6 creates a Temporary File in a Directory with Insecure Permissions. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.
Otros productos de Beyondtrust
Privileged Remote Access · 11Remote Support · 10Beyondinsight Password Safe · 2U-series Appliance · 2Beyondinsight · 2Privilege Management FOR MAC · 2Appliance Base Software · 1Privilege Management FOR Unix/linux · 1Privilege Management FOR Windows AND MAC · 1Privileged Identity · 1Beyondtrust Provider · 1Avecto Defendpoint · 1