CVE-2024-1591: Privilege Management for Windows < 24.1 Information Leak
Prior to version 24.1, a local authenticated attacker can view Sysvol when Privilege Management for Windows is configured to use a GPO policy. This allows them to view the policy and potentially find configuration issues.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Privilege Management for Windowsto a version that resolves this vulnerability.Fixed in 24.1
Event History
Frequently Asked Questions
What is the severity of CVE-2024-1591?
CVE-2024-1591 is classified as having a medium severity due to the potential for local authenticated attackers to exploit the vulnerability.
How do I fix CVE-2024-1591?
To fix CVE-2024-1591, upgrade BeyondTrust Privilege Management for Windows to version 24.1 or later.
Who is affected by CVE-2024-1591?
CVE-2024-1591 affects users of BeyondTrust Privilege Management for Windows versions prior to 24.1.
What type of attacker can exploit CVE-2024-1591?
CVE-2024-1591 can be exploited by local authenticated attackers.
What can be accessed by exploiting CVE-2024-1591?
Exploiting CVE-2024-1591 allows attackers to view Sysvol and potentially identify configuration issues.