Privilege escalation in Windows agent
Vulnerability Description
Incorrect permissions on the Checkmk Windows Agent's data directory in Checkmk < 2.3.0p8, < 2.2.0p29, < 2.1.0p45, and <= 2.0.0p39 (EOL) allows a local attacker to gain SYSTEM privileges.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-28827
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- modzero GmbH
References
More from Checkmk GmbH
View All →Affected Vendor
Checkmk GmbH
View all reports →