CVE-2023-49944: Medium severity beyondtrust privilege management vulnerability
The Challenge Response feature of BeyondTrust Privilege Management for Windows (PMfW) before 2023-07-14 allows local administrators to bypass this feature by decrypting the shared key, or by locating the decrypted shared key in process memory. The threat is mitigated by the Agent Protection feature.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-49944?
CVE-2023-49944 is considered a high severity vulnerability due to its potential exploitation by local administrators.
How do I fix CVE-2023-49944?
To fix CVE-2023-49944, upgrade BeyondTrust Privilege Management for Windows to version 2023-07-14 or later.
Who is affected by CVE-2023-49944?
CVE-2023-49944 affects users of BeyondTrust Privilege Management for Windows versions prior to 2023-07-14.
What is the impact of CVE-2023-49944?
The impact of CVE-2023-49944 allows local administrators to bypass the Challenge Response feature, compromising security.
What mitigation is in place for CVE-2023-49944?
The threat of CVE-2023-49944 is mitigated by the Agent Protection feature in BeyondTrust Privilege Management for Windows.