Critical BeyondTrust EPM Flaws Let Attackers Escalate Privileges
Key Takeaways BeyondTrust has disclosed two high-severity vulnerabilities affecting its Endpoint Privilege Management (EPM) for Windows. The flaws, CVE-2026-40144 and CVE-2026-40145, could allow...
Key Takeaways
- BeyondTrust has disclosed two high-severity vulnerabilities affecting its Endpoint Privilege Management (EPM) for Windows.
- The flaws, CVE-2026-40144 and CVE-2026-40145, could allow local attackers to escalate privileges or bypass security controls.
- All versions of BeyondTrust EPM (Windows Deployment) prior to 26.1.2 are affected.
- BeyondTrust discovered the issues internally and has found no evidence of exploitation in the wild.
- A patch is available, and organizations should update to version 26.1.2 or later immediately.
Critical BeyondTrust EPM Flaws Expose Windows Systems to Privilege Escalation
BeyondTrust has issued a security advisory detailing two high-severity vulnerabilities within its Endpoint Privilege Management (EPM) product for Windows. These critical flaws could enable malicious actors with local access to a system to elevate their privileges or circumvent crucial anti-tamper mechanisms designed to protect the EPM solution itself.
Table Of Content
The vulnerabilities, identified as CVE-2026-40144 and CVE-2026-40145, impact all iterations of BeyondTrust Endpoint Privilege Management (Windows Deployment) released before version 26.1.2. The company formally announced these issues in advisory BT26-04 on August 17, 2026.
According to BeyondTrust, these security defects were uncovered during internal security assessments, which leveraged advanced AI models and proprietary testing frameworks. The vendor stated that, at the time of remediation, there was no indication that either vulnerability had been exploited by external threat actors.
CVE-2026-40144: Kernel Privilege Escalation
The more severe of the two vulnerabilities, CVE-2026-40144, has been assigned a CVSS v4 score of 7.3, categorizing it as high severity. This flaw is an out-of-bounds read, classified as CWE-125, residing within a kernel-mode component of BeyondTrust EPM for Windows.
The root cause of this vulnerability lies in insufficient input validation within the affected kernel component. A local attacker, operating with standard, non-administrative user privileges, could exploit this weakness to force the component to access memory beyond its allocated boundaries.
Successful exploitation of CVE-2026-40144 could lead to kernel memory corruption and the execution of arbitrary code in kernel mode. Given that kernel mode operates at the highest privilege level within a Windows operating system, an attacker could achieve complete control over the compromised endpoint.
While this vulnerability requires local access, meaning it cannot be directly exploited remotely, local privilege escalation bugs are frequently a critical component of sophisticated attack chains. Threat actors often leverage such flaws after gaining an initial foothold on a system through other means, such as phishing, malware deployment, or stolen credentials, to escalate their access from a low-privileged user to full system administrator.
CVE-2026-40145: Anti-Tamper Bypass
The second vulnerability, CVE-2026-40145, carries a CVSS v4 score of 7.1. This issue is categorized as an insufficient access control vulnerability (CWE-1220), stemming from how a BeyondTrust EPM support utility interacts with the product’s built-in anti-tamper protections.
Under specific, predefined conditions, the security protections intended for the support utility process may not be correctly enforced. This could allow an attacker who has already achieved elevated privileges on an endpoint to manipulate the utility, thereby executing code outside the intended scope of EPM’s anti-tamper controls.
Unlike CVE-2026-40144, this flaw mandates that an attacker already possesses elevated privileges, local access, and specific endpoint preconditions. While CVE-2026-40145 does not provide an initial pathway to administrative access, it could significantly aid attackers in weakening existing security controls once they have already gained a privileged position on a system.
BeyondTrust has fixed both issues in Endpoint Privilege Management (Windows Deployment) version 26.1.2. Organizations utilizing affected versions are strongly advised to upgrade their endpoints to version 26.1.2 or a newer release without delay.
What You Should Do
- Immediately upgrade all BeyondTrust Endpoint Privilege Management (Windows Deployment) installations to version 26.1.2 or a later release.
- Review system logs for any unusual local privilege escalation attempts.
- Monitor for unexpected kernel-level crashes or suspicious process behavior involving EPM support utilities.
- Investigate any attempts to disable or interfere with endpoint security controls.
- Reinforce the principle of least privilege across your environment to minimize the impact of any potential local compromise.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.