CVE-2024-39708
CVE-2024-39708: Privilege escalation vulnerability in Delinea Privilege Manager impacting Windows systems. Non-admin users can exploit this to gain elevated permissions.
CVE-2024-39708 allows a local, non-administrator user to potentially escalate their privileges within Delinea Privilege Manager (formerly Thycotic Privilege Manager) on Windows systems prior to version 12.0.1096. This occurs because a crafted DLL file can be placed in a temporary directory, enabling privilege escalation when the core agent service loads it. Despite a CVSS score of 0, the CWE-427 designation highlights the potential for uncontrolled resource consumption, and the SVRS of 30, while not critical, indicates a moderate level of risk. Though the risk is moderate according to SVRS, the "In The Wild" tag indicates that this exploit is actively being used, meaning immediate patching should be considered. Exploiting this vulnerability could allow attackers to perform actions that require administrative rights, compromising system security.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.