An issue was discovered in BeyondTrust Privilege Management for Windows through 5.6. When adding the Add Admin token to a process, and specifying that it runs at medium integrity with the user owning the process, this security token can be stolen and applied to arbitrary processes.
2023-12-12T13:15:06.820
2024-11-21T04:59:55.607
Modified
CVSSv3.1: 7.8 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | beyondtrust | privilege_management_for_windows | < 5.6 | Yes |
Application | beyondtrust | privilege_management_for_windows | 5.6 | Yes |