VYPR
patchPublished Aug 19, 2026· 1 source

BeyondTrust EPM Vulnerabilities Enable Local Privilege Escalation

BeyondTrust has disclosed two high-severity vulnerabilities, CVE-2026-40144 and CVE-2026-40145, in its Endpoint Privilege Management for Windows, allowing local attackers to escalate privileges.

BeyondTrust has announced the discovery of two significant vulnerabilities within its Endpoint Privilege Management (EPM) solution for Windows. These flaws, identified as CVE-2026-40144 and CVE-2026-40145, affect all versions of the product released prior to version 26.1.2. The vulnerabilities were found internally by BeyondTrust during security assessments utilizing advanced AI models and proprietary testing tools. The company has confirmed that there is no evidence of these vulnerabilities being exploited in the wild before the release of patches.

The more critical of the two, CVE-2026-40144, carries a CVSS v4 score of 7.3 and is categorized as high severity. This vulnerability stems from an out-of-bounds read issue within a kernel-mode component of BeyondTrust EPM for Windows. The flaw arises because the component fails to adequately validate certain inputs, potentially allowing a local attacker with standard user privileges to access memory outside its designated boundaries. Successful exploitation could lead to kernel memory corruption and the execution of arbitrary code in kernel mode, granting an attacker complete control over the affected endpoint.

While CVE-2026-40144 requires local access, making it unsuitable for direct internet-based attacks, it remains a valuable target for threat actors. Such privilege escalation vulnerabilities are often chained with other initial access techniques, like phishing or malware infections, to elevate a compromised low-privileged account to administrative status.

The second vulnerability, CVE-2026-40145, has a CVSS v4 score of 7.1 and is classified as an insufficient access control issue. This flaw involves an interaction between a BeyondTrust EPM support utility and the product's anti-tamper mechanisms. Under specific circumstances, the anti-tamper protections applied to the support utility process might not be enforced correctly. This could enable an attacker who already possesses elevated privileges on an endpoint to manipulate the utility and execute code beyond the intended scope of EPM's security controls.

Exploiting CVE-2026-40145 is more complex, requiring an attacker to already have elevated privileges, local access, and specific endpoint conditions to be met. While it doesn't offer an initial pathway to administrator rights, it can be used by attackers to weaken existing security measures once they have gained a foothold with elevated permissions.

BeyondTrust has addressed both vulnerabilities by releasing version 26.1.2 of Endpoint Privilege Management (Windows Deployment). The company strongly advises all organizations using affected versions to upgrade to the latest version as soon as possible to mitigate the risks.

In addition to patching, security teams are encouraged to monitor their systems for any signs of unusual local privilege escalation activity, unexpected kernel crashes, suspicious behavior from EPM support utilities, or attempts to disable endpoint security controls. These proactive measures can help detect and respond to potential compromises.

This disclosure underscores the critical importance of maintaining robust security for privilege management tools. These solutions often operate with elevated permissions and are responsible for enforcing crucial security boundaries, making vulnerabilities within their kernel components or anti-tamper features particularly attractive to malicious actors.

Synthesized by Vypr AI