VYPR
High severity7.8NVD Advisory· Published Dec 12, 2023· Updated Jun 17, 2026

CVE-2020-12615

CVE-2020-12615

Description

An issue was discovered in BeyondTrust Privilege Management for Windows through 5.6. When adding the Add Admin token to a process, and specifying that it runs at medium integrity with the user owning the process, this security token can be stolen and applied to arbitrary processes.

Affected products

4
  • cpe:2.3:a:beyondtrust:privilege_management_for_windows:*:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:a:beyondtrust:privilege_management_for_windows:*:*:*:*:*:*:*:*range: <5.6
    • cpe:2.3:a:beyondtrust:privilege_management_for_windows:5.6:-:*:*:*:*:*:*
    • (no CPE)
    • (no CPE)range: <=5.6

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.