Intelligence View
CVE-2020-28369 | BeyondTrust Privilege Management up to 5.7 on Windows Installation Cryptbase.dll temp file
A vulnerability classified as critical has been found in BeyondTrust Privilege Management up to 5.7 on Windows. Affected is an unknown function in the library Cryptbase.dll of the component Installation. The manipulation leads to insecure…
This vulnerability is traded as CVE-2020-28369. Local access is required to approach this attack. There is no exploit available.
SOC Incident Playbook: Vulnerability Remediation & Verification
title: Detect Exploitation - CVE-2020-28369 | BeyondTrust Privilege Management up to 5.7 on Windows Installation Cryptbase.dll temp file
id: b48c7568-fae6-4b35-98fa-1be81d790a21
status: experimental
description: Automatisch generierte SIEM-Erkennungsregel basierend auf CTI Intelligence
references:
- https://tsecurity.de/
author: iShareStuff CTI Automated Detection Engine
date: 2026-09-23
logsource:
category: network_connection
product: any
detection:
selection:
CommandLine|contains:
- 'exploit'
condition: selection
falsepositives:
- Legitime administrative Zugriffe oder Penetrationstests
level: high
tags:
- attack.initial_accessrule CTI_Threat_Indicator {
meta:
author = "iShareStuff CTI Automated Detection Engine"
date = "2026-09-23"
description = "YARA Signature for "
strings:
$str = "CVE-2020-28369 | BeyondTrust P" ascii wide
condition:
any of them
}
SOCIAL SHARE CARD GENERATOR