CVE Vulnerabilities

CVE-2023-49944

Published: Dec 25, 2023 | Modified: Jan 03, 2024
CVSS 3.x
6.7
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

The Challenge Response feature of BeyondTrust Privilege Management for Windows (PMfW) before 2023-07-14 allows local administrators to bypass this feature by decrypting the shared key, or by locating the decrypted shared key in process memory. The threat is mitigated by the Agent Protection feature.

Affected Software

Name Vendor Start Version End Version
Privilege_management_for_windows Beyondtrust * 2023-07-14 (excluding)

References