CVE-2021-3187: High severity beyondtrust privilege management for windows and mac vulnerability
An issue was discovered in BeyondTrust Privilege Management for Mac before 5.7. An authenticated, unprivileged user can elevate privileges by running a malicious script (that executes as root from a temporary directory) during install time. (This applies to macOS before 10.15.5, or Security Update 2020-003 on Mojave and High Sierra, Later versions of macOS are not vulnerable.)
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-3187?
CVE-2021-3187 is considered a high-severity vulnerability due to its potential for privilege escalation.
How do I fix CVE-2021-3187?
To fix CVE-2021-3187, upgrade BeyondTrust Privilege Management for Mac to version 5.7 or later.
Who is affected by CVE-2021-3187?
CVE-2021-3187 affects authenticated, unprivileged users of BeyondTrust Privilege Management for Mac versions prior to 5.7 on certain macOS versions.
What are the consequences of exploiting CVE-2021-3187?
Exploiting CVE-2021-3187 allows an attacker to elevate privileges and execute commands as the root user.
What versions of macOS are vulnerable to CVE-2021-3187?
CVE-2021-3187 impacts macOS versions prior to 10.15.5 and specific updates of macOS Yosemite.