Incorrect Permissions on Checkmk Windows Agent Data Directory Leads to SYSTEM Privileges Escalation
CVE-2024-28827
7.8HIGH
Summary
The Checkmk Windows Agent is susceptible to a local privilege escalation vulnerability due to incorrect permissions set on its data directory. This issue affects versions prior to 2.3.0p8, 2.2.0p29, 2.1.0p45, and the end-of-life version 2.0.0p39. A local attacker can exploit this vulnerability to attain SYSTEM privileges, leading to unauthorized access and control over the affected system. Administrators are encouraged to review their installations of Checkmk and ensure that they have updated to a secure version to mitigate this risk.
Affected Version(s)
Checkmk 2.3.0 < 2.3.0p8
Checkmk 2.2.0 < 2.2.0p29
Checkmk 2.1.0 < 2.1.0p45
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
modzero GmbH