CVE-2021-44049
HIGHCyberark Endpoint Privilege Manager - Exposure to Wrong Actor
Title source: ruleDescription
CyberArk Endpoint Privilege Manager (EPM) through 11.5.3.328 before 2021-12-20 allows a local user to gain elevated privileges via a Trojan horse Procmon64.exe in the user's Temp directory.
References (4)
Scores
CVSS v3
7.8
EPSS
0.0005
EPSS Percentile
16.1%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-668
Status
published
Affected Products (2)
cyberark/endpoint_privilege_manager
< 11.5.4.355
cyberark/endpoint_privilege_manager
< 11.5.4.500
Timeline
Published
Jan 15, 2022
Tracked Since
Feb 18, 2026