Impact
Rapid7 InsightVM, Nexpose, and Insight Agent can execute discovered executables during authenticated assessment without validating file ownership. This flaw enables a local low‑privileged user to launch arbitrary code that runs with the privilege level of the scan credential, or even as root or SYSTEM when the Insight Agent is involved. The result is a local privilege escalation that compromises the confidentiality, integrity, and availability of the affected host. The weakness corresponds to CWE‑250, which addresses improper enforcement of authorization.
Affected Systems
The vulnerability affects Rapid7 Insight Agent, Rapid7 InsightVM, and Rapid7 Nexpose. Systems running older content are potentially exposed; the fix requires updating to Scan Engine content 1.1.3935 or later for InsightVM and Nexpose, and to Insight Agent content component 0.0.245.0 or later. Internet‑connected deployments receive these updates automatically through content updates; air‑gapped or offline environments must apply the corresponding offline content update.
Risk and Exploitability
The CVSS score of 7.8 indicates a high‑severity local privilege escalation. The EPSS score of less than 1 % suggests a very low current exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. An attacker would need local authenticated access to the system and the ability to place an executable for the scan engine to discover; once present, execution can occur without further validation. The attack vector is local and requires permission to trigger a scan on the affected system.
OpenCVE Enrichment