BeyondTrust Patches Critical Windows EPM Vulnerabilities

BeyondTrust has recently addressed two significant security vulnerabilities in its Endpoint Privilege Management (EPM) solution for Windows, which could potentially allow attackers with local access to escalate privileges or bypass anti-tamper mechanisms.

Identified as CVE-2026-40144 and CVE-2026-40145, these flaws impact all versions of BeyondTrust EPM for Windows released prior to version 26.1.2. The company released advisory BT26-04 on August 17, 2026, detailing these issues.

Details of the Vulnerabilities

The more severe of the two, CVE-2026-40144, has been assigned a CVSS v4 score of 7.3, categorizing it as high severity. This vulnerability arises from an out-of-bounds read error in a kernel-mode component of BeyondTrust EPM for Windows. The issue stems from inadequate validation of specific inputs, allowing a local user with standard privileges to potentially access memory beyond intended boundaries. Exploiting this flaw could lead to kernel memory corruption and arbitrary code execution in kernel mode, granting the attacker full control over the affected system.

The second vulnerability, CVE-2026-40145, carries a CVSS v4 score of 7.1. It involves insufficient access controls related to the interaction between a BeyondTrust EPM support utility and the product’s anti-tamper protections. Under certain conditions, the anti-tamper measures may not function as intended, enabling an attacker with already elevated privileges to manipulate the support utility and execute code outside the scope of EPM’s protections. While this flaw does not provide an initial pathway to administrative access, it could be exploited to weaken security controls once privileged access has been obtained.

Discovery and Mitigation

BeyondTrust discovered these vulnerabilities internally during security assessments utilizing advanced AI models and proprietary testing tools. The company has found no evidence of these flaws being exploited prior to their remediation.

To address these issues, BeyondTrust has released version 26.1.2 of its Endpoint Privilege Management for Windows. Organizations using affected versions are strongly advised to upgrade their systems to this latest version promptly. Additionally, security teams should monitor for unusual local privilege escalation activities, unexpected kernel-level crashes, suspicious behaviors involving EPM support utilities, and any attempts to disable or interfere with endpoint security controls.

These vulnerabilities underscore the critical importance of promptly patching privilege management tools. Such products often operate with elevated permissions and enforce essential security boundaries, making any weaknesses in their kernel components or anti-tamper mechanisms particularly attractive targets for attackers.