CVE-2018-10959: BeyondTrust Avecto Defendpoint

High severity, CVSS 7.5. EPSS: 1.6% chance of exploitation in the next 30 days.

Avecto Defendpoint 4 prior to 4.4 SR6 and 5 prior to 5.1 SR1 has an Untrusted Search Path vulnerability, exploitable by modifying environment variables to trigger automatic elevation of an attacker's process launch.

Affected products

  • BeyondTrust Avecto Defendpoint: from 4.0, before 4.4.267.0 (fixed in 4.4.267.0); from 5.0, before 5.1.149.0 (fixed in 5.1.149.0)

Published 2019-04-17. Last modified 2026-06-17.