Vulnerabilities > Beyondtrust

DATE CVE VULNERABILITY TITLE RISK
2020-03-18 CVE-2020-9326 Unspecified vulnerability in Beyondtrust Privilege Management for Windows and mac
BeyondTrust Privilege Management for Windows and Mac (aka PMWM; formerly Avecto Defendpoint) 5.1 through 5.5 before 5.5 SR1 mishandles command-line arguments with PowerShell .ps1 file extensions present, leading to a DefendpointService.exe crash.
network
low complexity
beyondtrust
7.5
2019-04-17 CVE-2018-10959 Untrusted Search Path vulnerability in Beyondtrust Avecto Defendpoint
Avecto Defendpoint 4 prior to 4.4 SR6 and 5 prior to 5.1 SR1 has an Untrusted Search Path vulnerability, exploitable by modifying environment variables to trigger automatic elevation of an attacker's process launch.
network
low complexity
beyondtrust CWE-426
7.5
2017-10-26 CVE-2017-5996 Untrusted Search Path vulnerability in Beyondtrust Remote Support
The agent in Bomgar Remote Support 15.2.x before 15.2.3, 16.1.x before 16.1.5, and 16.2.x before 16.2.4 allows DLL hijacking because of weak %SYSTEMDRIVE%\ProgramData permissions.
local
low complexity
beyondtrust CWE-426
7.8