Incorrect Permissions on Checkmk Windows Agent Data Directory Leads to SYSTEM Privileges Escalation
CVE-2024-28827
What is CVE-2024-28827?
The Checkmk Windows Agent is susceptible to a local privilege escalation vulnerability due to incorrect permissions set on its data directory. This issue affects versions prior to 2.3.0p8, 2.2.0p29, 2.1.0p45, and the end-of-life version 2.0.0p39. A local attacker can exploit this vulnerability to attain SYSTEM privileges, leading to unauthorized access and control over the affected system. Administrators are encouraged to review their installations of Checkmk and ensure that they have updated to a secure version to mitigate this risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Checkmk 2.3.0 < 2.3.0p8
Checkmk 2.2.0 < 2.2.0p29
Checkmk 2.1.0 < 2.1.0p45
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
