Incorrect Permissions on Checkmk Windows Agent Data Directory Leads to SYSTEM Privileges Escalation
CVE-2024-28827
7.8HIGH
What is CVE-2024-28827?
The Checkmk Windows Agent is susceptible to a local privilege escalation vulnerability due to incorrect permissions set on its data directory. This issue affects versions prior to 2.3.0p8, 2.2.0p29, 2.1.0p45, and the end-of-life version 2.0.0p39. A local attacker can exploit this vulnerability to attain SYSTEM privileges, leading to unauthorized access and control over the affected system. Administrators are encouraged to review their installations of Checkmk and ensure that they have updated to a secure version to mitigate this risk.
Affected Version(s)
Checkmk 2.3.0 < 2.3.0p8
Checkmk 2.2.0 < 2.2.0p29
Checkmk 2.1.0 < 2.1.0p45