The Challenge Response feature of BeyondTrust Privilege Management for Windows (PMfW) before 2023-07-14 allows local administrators to bypass this feature by decrypting the shared key, or by locating the decrypted shared key in process memory. The threat is mitigated by the Agent Protection feature.
References
Link | Resource |
---|---|
https://www.beyondtrust.com/security | Vendor Advisory |
https://www.beyondtrust.com/trust-center/security-advisories/bt23-08 | Vendor Advisory |
Configurations
History
No history.
Information
Published : 2023-12-25 08:15
Updated : 2024-01-03 22:53
NVD link : CVE-2023-49944
Mitre link : CVE-2023-49944
CVE.ORG link : CVE-2023-49944
JSON object : View
Products Affected
beyondtrust
- privilege_management_for_windows
CWE