PT-2024-28645 · Delinea · Delinea Privilege Manager

Brenden Meeder

·

Published

2024-06-27

·

Updated

2024-10-31

·

CVE-2024-39708

CVSS v3.1

7.0

High

VectorAC:H/AV:L/A:H/C:H/I:H/PR:L/S:U/UI:N
Name of the Vulnerable Software and Affected Versions Delinea Privilege Manager versions prior to 12.0.1096
Description A local privilege escalation issue was discovered in Delinea Privilege Manager, allowing a non-administrator user to potentially execute arbitrary code as SYSTEM by exploiting a dynamic-link library (DLL) search order hijacking vulnerability. This occurs when the core agent service loads a crafted DLL file from a temporary directory used by .NET Shadow Copies.
Recommendations For versions prior to 12.0.1096, update to version 12.0.1096 or later to resolve the issue. As a temporary workaround, consider restricting access to the temporary directory used by .NET Shadow Copies to minimize the risk of exploitation.

Fix

Uncontrolled Search Path Element

Weakness Enumeration

Related Identifiers

CVE-2024-39708

Affected Products

Delinea Privilege Manager