Home/Product/beyondtrust privilege management for windows
Product

beyondtrust privilege management for windows

12 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-6250
< 25.4.270
Prior to 25.4.270.0, when wmic.exe is elevated with a full admin token the user can stop the Defendpoint service, bypassing anti-t
6.7MEDIUM
CVE-2025-2297
< 25.4.270
Prior to version 25.4.270.0, a local authenticated attacker can manipulate user profile files to add illegitimate challenge respon
7.8HIGH
CVE-2025-0889
< 25.2
Prior to 25.2, a local authenticated attacker can elevate privileges on a system with Privilege Management for Windows installed,
7.8HIGH
CVE-2024-25083
< 24.1
An issue was discovered in BeyondTrust Privilege Management for Windows before 24.1. When an low-privileged user initiates a repai
6.3MEDIUM
CVE-2024-1591
< 24.1
Prior to version 24.1, a local authenticated attacker can view Sysvol when Privilege Management for Windows is configured to use a
3.3LOW
CVE-2023-49944
< 2023-07-14
The Challenge Response feature of BeyondTrust Privilege Management for Windows (PMfW) before 2023-07-14 allows local administrator
6.7MEDIUM
CVE-2020-28369
<= 5.7
In BeyondTrust Privilege Management for Windows (aka PMfW) through 5.7, a SYSTEM installation causes Cryptbase.dll to be loaded fr
7.8HIGH
CVE-2020-12614
<= 5.6
An issue was discovered in BeyondTrust Privilege Management for Windows through 5.6. If the publisher criteria is selected, it def
7.8HIGH
CVE-2020-12612
< 5.6
An issue was discovered in BeyondTrust Privilege Management for Windows through 5.6. When specifying a program to elevate, it can
7.8HIGH
CVE-2020-12615
< 5.6
An issue was discovered in BeyondTrust Privilege Management for Windows through 5.6. When adding the Add Admin token to a process,
7.8HIGH
CVE-2020-12613
<= 5.6
An issue was discovered in BeyondTrust Privilege Management for Windows through 5.6. An attacker can spawn a process with multiple
8.8HIGH
CVE-2021-42254
< 21.6
BeyondTrust Privilege Management prior to version 21.6 creates a Temporary File in a Directory with Insecure Permissions.
7.8HIGH
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin