CVE-2024-25083: High severity BeyondTrust Privilege Management for Windows vulnerability
An issue was discovered in BeyondTrust Privilege Management for Windows before 24.1. When an low-privileged user initiates a repair, there is an attack vector through which the user is able to execute any program with elevated privileges.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-25083?
CVE-2024-25083 is considered a critical vulnerability due to its potential to allow low-privileged users to execute programs with elevated privileges.
How do I fix CVE-2024-25083?
To fix CVE-2024-25083, upgrade BeyondTrust Privilege Management for Windows to version 24.1 or later.
Who is affected by CVE-2024-25083?
CVE-2024-25083 affects users of BeyondTrust Privilege Management for Windows versions prior to 24.1.
What is the attack vector associated with CVE-2024-25083?
The attack vector for CVE-2024-25083 arises when a low-privileged user initiates a repair process which can lead to elevated privilege execution.
Is there a workaround for CVE-2024-25083?
Currently, there is no officially recommended workaround for CVE-2024-25083, and updating the software is the best course of action.