Cyber Resilience

CVE-2023-49944

Beyondtrust Privilege Management For Windows ≤ 2023-07-14

Published
25 December 2023
Modified
21 November 2024
Patch / advisory
CVSS Score v3.1 6.7
Click a component to see what it means
Raw vectorCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS Score 0.0019 8th percentile
Risk Priority 48 floored blend · peak EPSS

Summary

CVE-2023-49944 is a medium-severity an unspecified weakness vulnerability in Beyondtrust Privilege Management For Windows. Its CVSS base score is 6.7 (Medium).

Operationally, ranked at the 8th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

EU & UK References

Vulnerability Data

The Challenge Response feature of BeyondTrust Privilege Management for Windows (PMfW) before 2023-07-14 allows local administrators to bypass this feature by decrypting the shared key, or by locating the decrypted shared key in process memory. The threat is mitigated by…

more

the Agent Protection feature.

CWE(s)

Related Threats

CVEs Like This One

CVE-2025-0889Same product: Beyondtrust Privilege Management For Windows
CVE-2025-2297Same product: Beyondtrust Privilege Management For Windows
CVE-2024-1591Same product: Beyondtrust Privilege Management For Windows
CVE-2024-25083Same product: Beyondtrust Privilege Management For Windows
CVE-2025-6250Same product: Beyondtrust Privilege Management For Windows
CVE-2024-12686Same vendor: Beyondtrust
CVE-2024-9110Same vendor: Beyondtrust
CVE-2024-4220Same vendor: Beyondtrust
CVE-2024-5812Same vendor: Beyondtrust
CVE-2025-0217Same vendor: Beyondtrust

Affected Assets

beyondtrust
privilege management for windows
≤ 2023-07-14

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References