First published: Tue Dec 12 2023(Updated: )
In BeyondTrust Privilege Management for Windows (aka PMfW) through 5.7, a SYSTEM installation causes Cryptbase.dll to be loaded from the user-writable location %WINDIR%\Temp.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
BeyondTrust Privilege Management for Windows | <=5.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-28369 is considered a high severity vulnerability due to its potential to allow code execution from user-writable locations.
To mitigate CVE-2020-28369, ensure that BeyondTrust Privilege Management for Windows is upgraded to a version above 5.7.
CVE-2020-28369 affects all versions of BeyondTrust Privilege Management for Windows up to and including version 5.7.
The impact of CVE-2020-28369 includes the risk of unauthorized code execution from the %WINDIR%\Temp directory.
CVE-2020-28369 poses a significant risk for organizations using affected versions of BeyondTrust Privilege Management, potentially leading to security breaches.