Impact
Local privilege escalation arises in Checkmk 2.5.0 before 2.5.0p10 when a user who can edit the Oracle Instant Client reference used by the mk-oracle agent plugin can cause the agent to run actions with higher privileges. The flaw permits the attacker to gain elevated privileges on the host hosting the affected agent, compromising confidentiality, integrity, and availability of that system.
Affected Systems
Checkmk released by Checkmk GmbH is affected. Versions prior to 2.5.0p10, specifically 2.5.0 up to 2.5.0p9, contain the vulnerable mk-oracle plugin.
Risk and Exploitability
The CVSS score of 5.2 indicates a medium severity vulnerability. The attack vector is local and requires that the attacker has permission to edit plugin settings. The EPSS score is not available and the issue is not listed in CISA’s KEV catalog, so the probability of exploitation is unknown, but the local nature and privilege requirement suggest that only users with elevated access can exploit it. Nonetheless, the ability to elevate privileges on an impacted node makes it a significant risk within a compromised local environment.
OpenCVE Enrichment