Local Privilege Escalation in Rapid7 Insight Agent - Rapid7
CVE-2019-5629

7.8HIGH

Key Information:

Vendor

Rapid7

Vendor
CVE Published:
13 July 2019

What is CVE-2019-5629?

The Rapid7 Insight Agent versions 2.6.3 and earlier are susceptible to a local privilege escalation vulnerability due to an uncontrolled DLL search path. When the agent is initiated, the Python interpreter attempts to load 'python3.dll' from a writeable directory ('C:\DLLs\python3.dll'), which can be exploited by a malicious local user to gain SYSTEM privileges. This issue has been addressed in version 2.6.4 of the Insight Agent.

Affected Version(s)

Insight Agent 2.6.3 and prior

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This issue was discovered, and reported to Rapid7, by independent researcher Florian Bogner at Bee IT Security. It is being disclosed in accordance with Rapid7's vulnerability disclosure policy (https://www.rapid7.com/disclosure/).
.