Description
Rapid7 Insight Agent versions 3.1.2.38 and earlier suffer from a privilege escalation vulnerability, whereby an attacker can hijack the flow of execution due to an unquoted argument to the runas.exe command used by the ir_agent.exe component, resulting in elevated rights and persistent access to the machine. This issue was fixed in Rapid7 Insight Agent version 3.1.3.80.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-15432 | Rapid7 Insight Agent versions 3.1.2.38 and earlier suffer from a privilege escalation vulnerability, whereby an attacker can hijack the flow of execution due to an unquoted argument to the runas.exe command used by the ir_agent.exe component, resulting in elevated rights and persistent access to the machine. This issue was fixed in Rapid7 Insight Agent version 3.1.3.80. |
References
History
No history.
Status: PUBLISHED
Assigner: rapid7
Published:
Updated: 2024-09-16T20:01:39.262Z
Reserved: 2022-01-14T00:00:00.000Z
Link: CVE-2022-0237
No data.
Status : Modified
Published: 2022-03-17T23:15:07.523
Modified: 2024-11-21T06:38:12.433
Link: CVE-2022-0237
No data.
OpenCVE Enrichment
No data.
EUVD