Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-0237

Опубликовано: 17 мар. 2022
Источник: nvd
CVSS3: 4
CVSS3: 7.8
CVSS2: 7.2
EPSS Низкий

Описание

Rapid7 Insight Agent versions 3.1.2.38 and earlier suffer from a privilege escalation vulnerability, whereby an attacker can hijack the flow of execution due to an unquoted argument to the runas.exe command used by the ir_agent.exe component, resulting in elevated rights and persistent access to the machine. This issue was fixed in Rapid7 Insight Agent version 3.1.3.80.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:rapid7:insight_agent:*:*:*:*:*:*:*:*
Версия до 3.1.2.38 (включая)

EPSS

Процентиль: 19%
0.00061
Низкий

4 Medium

CVSS3

7.8 High

CVSS3

7.2 High

CVSS2

Дефекты

CWE-264
CWE-428

Связанные уязвимости

CVSS3: 7.8
github
почти 4 года назад

Rapid7 Insight Agent versions 3.1.2.38 and earlier suffer from a privilege escalation vulnerability, whereby an attacker can hijack the flow of execution due to an unquoted argument to the runas.exe command used by the ir_agent.exe component, resulting in elevated rights and persistent access to the machine. This issue was fixed in Rapid7 Insight Agent version 3.1.3.80.

EPSS

Процентиль: 19%
0.00061
Низкий

4 Medium

CVSS3

7.8 High

CVSS3

7.2 High

CVSS2

Дефекты

CWE-264
CWE-428