Executive brief
BeyondTrust Endpoint Privilege Management is a Windows security tool that manages and monitors privileged user access. A memory corruption vulnerability in its kernel-mode component could allow a local attacker to crash the system or potentially execute code with elevated privileges, disrupting endpoint protection and security policy enforcement.
Technical details
A memory-corruption vulnerability exists in a kernel-mode component of BeyondTrust Endpoint Privilege Management on Windows. The flaw is caused by insufficient validation of input processed by the component, resulting in out-of-bounds memory access. The vulnerability affects versions prior to 26.1.2 and requires local access to trigger. An attacker with local system access could exploit this to cause a denial of service or potentially achieve code execution at kernel privilege level. A fix is available in version 26.1.2 and later.
Affected products
- BeyondTrust Endpoint Privilege Management prior to 26.1.2
Timeline
- 2026-08-17: disclosed