First published: Fri Feb 16 2024(Updated: )
Prior to version 24.1, a local authenticated attacker can view Sysvol when Privilege Management for Windows is configured to use a GPO policy. This allows them to view the policy and potentially find configuration issues.
Credit: 13061848-ea10-403d-bd75-c83a022c2891
Affected Software | Affected Version | How to fix |
---|---|---|
BeyondTrust Privilege Management for Windows | <24.1 | |
BeyondTrust Privilege Management for Windows | <24.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-1591 is classified as having a medium severity due to the potential for local authenticated attackers to exploit the vulnerability.
To fix CVE-2024-1591, upgrade BeyondTrust Privilege Management for Windows to version 24.1 or later.
CVE-2024-1591 affects users of BeyondTrust Privilege Management for Windows versions prior to 24.1.
CVE-2024-1591 can be exploited by local authenticated attackers.
Exploiting CVE-2024-1591 allows attackers to view Sysvol and potentially identify configuration issues.