Delinea Privilege Manager before 12.0.2 mishandles the security of the Windows agent.
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
During installation, installed file permissions are set to allow anyone to modify those files.
Link | Tags |
---|---|
https://docs.delinea.com/online-help/privilege-manager/release-notes/12.0.2-combined.htm | release notes |
https://trust.delinea.com/?tcuUid=3be1a12c-97c9-431e-a51a-0c25da19ec86 | vendor advisory |