First published: Fri Feb 16 2024(Updated: )
An issue was discovered in BeyondTrust Privilege Management for Windows before 24.1. When an low-privileged user initiates a repair, there is an attack vector through which the user is able to execute any program with elevated privileges.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
BeyondTrust Privilege Management for Windows and Mac | <24.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-25083 is considered a critical vulnerability due to its potential to allow low-privileged users to execute programs with elevated privileges.
To fix CVE-2024-25083, upgrade BeyondTrust Privilege Management for Windows to version 24.1 or later.
CVE-2024-25083 affects users of BeyondTrust Privilege Management for Windows versions prior to 24.1.
The attack vector for CVE-2024-25083 arises when a low-privileged user initiates a repair process which can lead to elevated privilege execution.
Currently, there is no officially recommended workaround for CVE-2024-25083, and updating the software is the best course of action.