Incorrect Permissions on Checkmk Windows Agent Data Directory Leads to SYSTEM Privileges Escalation
CVE-2024-28827

7.8HIGH

Key Information:

Status
Vendor
CVE Published:
10 July 2024

Summary

The Checkmk Windows Agent is susceptible to a local privilege escalation vulnerability due to incorrect permissions set on its data directory. This issue affects versions prior to 2.3.0p8, 2.2.0p29, 2.1.0p45, and the end-of-life version 2.0.0p39. A local attacker can exploit this vulnerability to attain SYSTEM privileges, leading to unauthorized access and control over the affected system. Administrators are encouraged to review their installations of Checkmk and ensure that they have updated to a secure version to mitigate this risk.

Affected Version(s)

Checkmk 2.3.0 < 2.3.0p8

Checkmk 2.2.0 < 2.2.0p29

Checkmk 2.1.0 < 2.1.0p45

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

modzero GmbH
.