PT-2024-18155 · Beyondtrust · Privilege Management For Windows

Published

2024-02-16

·

Updated

2024-02-16

·

CVE-2024-1591

CVSS v3.1

3.3

Low

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Privilege Management for Windows versions prior to 24.1
Description A local authenticated attacker can view Sysvol when Privilege Management for Windows is configured to use a GPO policy, allowing them to view the policy and potentially find configuration issues.
Recommendations For versions prior to 24.1, update to version 24.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the Sysvol directory to minimize the risk of exploitation.

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2024-1591

Affected Products

Privilege Management For Windows