Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7c4x-gmcj-f3mw

Опубликовано: 19 мар. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.8

Описание

Rapid7 Insight Agent versions 3.1.2.38 and earlier suffer from a privilege escalation vulnerability, whereby an attacker can hijack the flow of execution due to an unquoted argument to the runas.exe command used by the ir_agent.exe component, resulting in elevated rights and persistent access to the machine. This issue was fixed in Rapid7 Insight Agent version 3.1.3.80.

Rapid7 Insight Agent versions 3.1.2.38 and earlier suffer from a privilege escalation vulnerability, whereby an attacker can hijack the flow of execution due to an unquoted argument to the runas.exe command used by the ir_agent.exe component, resulting in elevated rights and persistent access to the machine. This issue was fixed in Rapid7 Insight Agent version 3.1.3.80.

EPSS

Процентиль: 19%
0.00061
Низкий

7.8 High

CVSS3

Дефекты

CWE-428

Связанные уязвимости

CVSS3: 4
nvd
почти 4 года назад

Rapid7 Insight Agent versions 3.1.2.38 and earlier suffer from a privilege escalation vulnerability, whereby an attacker can hijack the flow of execution due to an unquoted argument to the runas.exe command used by the ir_agent.exe component, resulting in elevated rights and persistent access to the machine. This issue was fixed in Rapid7 Insight Agent version 3.1.3.80.

EPSS

Процентиль: 19%
0.00061
Низкий

7.8 High

CVSS3

Дефекты

CWE-428