CVE-2024-10526 - CVE House
Back to Database
Status published High CVE-2024-10526

Rapid7 Velociraptor Local Privilege Escalation In Windows Velociraptor Service

Vulnerability Description

Rapid7 Velociraptor MSI Installer versions below 0.73.3 suffer from a vulnerability whereby it creates the installation directory with WRITE_DACL permission to the BUILTIN\\Users group. This allows local users who are not administrators to grant themselves the Full Control permission on Velociraptor's files. By modifying Velociraptor's files, local users can subvert the binary and cause the Velociraptor service to execute arbitrary code as the SYSTEM user, or to replace the Velociraptor binary completely.  This issue is fixed in version 0.73.3.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-10526

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Jean-Baptiste Mesnard-Sense from Synackti

Affected Vendor

Affected Software

Velociraptor
Vulnerable Versions:
<0.73.2

Timeline

Official Publish: November 7th, 2024
Last Modified: November 7th, 2024
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)