Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-1591


Prior to version 24.1, a local authenticated attacker can view Sysvol when Privilege Management for Windows is configured to use a GPO policy. This allows them to view the policy and potentially find configuration issues.


Published

2024-02-16T19:15:08.207

Last Modified

2025-02-07T15:07:53.133

Status

Analyzed

Source

13061848-ea10-403d-bd75-c83a022c2891

Severity

CVSSv3.1: 3.3 (LOW)

Weaknesses
  • Type: Secondary
    CWE-200
  • Type: Primary
    NVD-CWE-noinfo

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application beyondtrust privilege_management_for_windows < 24.1 Yes

References