CVE-2024-1591: BeyondTrust Privilege Management For Windows

Low severity, CVSS 3.3. EPSS: 0.2% chance of exploitation in the next 30 days.

Prior to version 24.1, a local authenticated attacker can view Sysvol when Privilege Management for Windows is configured to use a GPO policy. This allows them to view the policy and potentially find configuration issues.

Affected products

  • BeyondTrust Privilege Management For Windows: before 24.1 (fixed in 24.1)

Published 2024-02-16. Last modified 2026-06-17.