CVE-2020-25738: Cyberark Endpoint Privilege Manager

Medium severity, CVSS 5.5. EPSS: 0.4% chance of exploitation in the next 30 days.

CyberArk Endpoint Privilege Manager (EPM) 11.1.0.173 allows attackers to bypass a Credential Theft protection mechanism by injecting a DLL into a process that normally has credential access, such as a Chrome process that reads credentials from a SQLite database.

Affected products

  • Cyberark Endpoint Privilege Manager: version 11.1.0.173 only

Published 2020-11-27. Last modified 2026-06-17.