ZeroHour

CVE-2020-12615

CVSS 3.1
7.8 high
EPSS
<1%p13
Published
()
Modified
Description

An issue was discovered in BeyondTrust Privilege Management for Windows through 5.6. When adding the Add Admin token to a process, and specifying that it runs at medium integrity with the user owning the process, this security token can be stolen and applied to arbitrary processes.

Vendors
beyondtrust
Products
privilege management for windows
Weakness
CWE-269
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.