Prior to version 24.1, a local authenticated attacker can view Sysvol when Privilege Management for Windows is configured to use a GPO policy. This allows them to view the policy and potentially find configuration issues.
2024-02-16T19:15:08.207
2025-02-07T15:07:53.133
Analyzed
13061848-ea10-403d-bd75-c83a022c2891
CVSSv3.1: 3.3 (LOW)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | beyondtrust | privilege_management_for_windows | < 24.1 | Yes |