Rapid7 Insight Agent Privilege Escalation
CVE-2021-4007

7.8HIGH

Key Information:

Vendor

Rapid7

Vendor
CVE Published:
14 December 2021

What is CVE-2021-4007?

Rapid7 Insight Agent, versions 3.0.1 to 3.1.2.34, suffer from a local privilege escalation due to an uncontrolled DLL search path. Specifically, when Insight Agent versions 3.0.1 to 3.1.2.34 start, the Python interpreter attempts to load python3.dll at "C:\DLLs\python3.dll," which normally is writable by locally authenticated users. Because of this, a malicious local user could use Insight Agent's startup conditions to elevate to SYSTEM privileges. This issue was fixed in Rapid7 Insight Agent 3.1.2.35. This vulnerability is a regression of CVE-2019-5629.

Affected Version(s)

Insight Agent 3.0.1 < 3.0.1*

Insight Agent 3.1.2.34

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dawson Medin discovered and disclosed this issue to Rapid7
.
CVE-2021-4007 : Rapid7 Insight Agent Privilege Escalation