Impact
A flaw exists in the interaction between a BeyondTrust Endpoint Privilege Management support utility and the agent’s tamper protection controls. When the advertised conditions are met, the protections that should apply to the utility process are not enforced correctly, allowing a malicious actor to perform actions against the utility as if they had legitimate privileges. The weakness is a failure of security checks (CWE-1220).
Affected Systems
The vulnerability affects BeyondTrust Endpoint Privilege Management for Windows deployment. No specific product version information is available from the advisory.
Risk and Exploitability
The CVSS score of 7.1 signifies a high severity issue. EPSS data is not available and the vulnerability is not listed in the CISA KEV catalog, indicating no widely publicized exploitation reports. The likely attack vector is local; an attacker who can run or manipulate the support utility on the target system would be able to bypass tamper protection, potentially enabling privileged code execution or unauthorized modifications.
OpenCVE Enrichment