• CVSSv3 Score: 5.5
  • Issue Date: 2020-08-01
  • Updated On: 2023-12-05
  • CVE(s): CVE-2020-28369

Synopsis:

DLL Hijacking in Privilege Management for Windows (PMfW) Installer

Impacted Product:

Privilege Management for Windows (PMfW)

Summary:

A medium-severity vulnerability was discovered and verified in BeyondTrust’s Privilege Management for Windows (PMfW) that allowed an attacker to hijack a DLL in the PMfW installer. The Privilege Management for Windows installer loads several DLLs during installation. In some instances, DLLs were loaded from user-controlled locations which could enable code injection.

Mitigation:

The search order of DLLs in the Privilege Management for Windows installer was changed to ensure only DLLs from trusted locations are loaded. This change was implemented in PMfW version 21.3. BeyondTrust recommends customers update to the latest version of PMfW as soon as possible.

Product Version
Privilege Management for Windows (PMfW) Prior to 23.1
Product Version
Privilege Management for Windows (PMfW) 23.1 and above

BeyondTrust would like to acknowledge Lockheed Martin Red team for reporting this issue.

References:

  1. https://www.cve.org/CVERecord?id=CVE-2020-28369
  2. https://nvd.nist.gov/vuln/detail/CVE-2020-28369
Prefers reduced motion setting detected. Animations will now be reduced as a result.