CVE-2024-39708: High severity delinea privileged access service vulnerability
An issue was discovered in the Agent in Delinea Privilege Manager (formerly Thycotic Privilege Manager) before 12.0.1096 on Windows. Sometimes, a non-administrator user can copy a crafted DLL file to a temporary directory (used by .NET Shadow Copies) such that privilege escalation can occur if the core agent service loads that file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-39708?
CVE-2024-39708 has a high severity rating due to the privilege escalation risk it poses.
How do I fix CVE-2024-39708?
To mitigate CVE-2024-39708, users should upgrade to Delinea Privilege Manager version 12.0.1096 or later.
Who is affected by CVE-2024-39708?
CVE-2024-39708 affects users of Delinea Privilege Manager versions prior to 12.0.1096 on Windows systems.
What type of vulnerability is CVE-2024-39708?
CVE-2024-39708 is classified as a local privilege escalation vulnerability.
Can a non-administrator user exploit CVE-2024-39708?
Yes, a non-administrator user can exploit CVE-2024-39708 to gain elevated privileges by copying a crafted DLL file.