Remote Code Execution Vulnerability in WhatsUp Gold Distributed Edition
CVE-2024-5016
7.2HIGH
Summary
The security vulnerability affects WhatsUp Gold, particularly in its Distributed Edition installations released before version 2023.1.3. The flaw is rooted in the message processing routines, specifically within NmDistributed.DistributedServiceBehavior.OnMessage for servers and NmDistributed.DistributedClient.OnMessage for clients. This vulnerability can be exploited via a deserialization tool, enabling an attacker to achieve Remote Code Execution with SYSTEM-level privileges, potentially compromising the integrity and confidentiality of the affected systems.
Affected Version(s)
WhatsUp Gold Windows 2023.1.0
References
CVSS V3.1
Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Collectors
NVD DatabaseMitre Database
Credit
Sina Kheirkhah (@SinSinology) of Summoning Team (@SummoningTeam) working with Trend Micro Zero Day Initiative