Vulnerabilities > Beyondtrust > High

DATE CVE VULNERABILITY TITLE RISK
2019-04-17 CVE-2018-10959 Untrusted Search Path vulnerability in Beyondtrust Avecto Defendpoint
Avecto Defendpoint 4 prior to 4.4 SR6 and 5 prior to 5.1 SR1 has an Untrusted Search Path vulnerability, exploitable by modifying environment variables to trigger automatic elevation of an attacker's process launch.
network
low complexity
beyondtrust CWE-426
7.5
2017-10-26 CVE-2017-5996 Untrusted Search Path vulnerability in Beyondtrust Remote Support
The agent in Bomgar Remote Support 15.2.x before 15.2.3, 16.1.x before 16.1.5, and 16.2.x before 16.2.4 allows DLL hijacking because of weak %SYSTEMDRIVE%\ProgramData permissions.
local
low complexity
beyondtrust CWE-426
7.8