Executive brief
BeyondTrust Endpoint Privilege Management is a Windows-based utility that manages privileged access and enforces security controls on sensitive processes. A vulnerability in the interaction between the support utility and tamper protection controls could allow an attacker to circumvent security protections, potentially enabling unauthorized process modification or privilege escalation on affected systems.
Technical details
The vulnerability exists in how the Endpoint Privilege Management (Windows Deployment) support utility interacts with the agent's tamper protection controls. Under certain conditions, the protections applied to the utility process may not be enforced as intended, creating a gap in the security enforcement mechanism. This is a logic flaw in the protection application layer rather than a memory safety issue. An attacker with local access could potentially exploit this to bypass tamper protection, though specific preconditions and exploitation techniques are not detailed in the available advisory text. Patches from BeyondTrust are expected.
Affected products
- BeyondTrust Endpoint Privilege Management <UNKNOWN>
Timeline
- 2026-08-17: disclosed