Impact
Velociraptor includes an artifact called Windows.Sysinternals.SysmonLogForward that is intended to forward Sysmon events to the server. The artifact accepts an arbitrary binary path as a parameter but does not enforce an additional required permission. Users who have typically assigned to the Investigator role, can collect this artifact from endpoints and, because of the missing permission check, can specify a malicious binary to be executed with elevated privileges. The vulnerability therefore allows the exploitation of privilege escalation by instructing endpoints to run an attacker‑controlled program with the privileges of the running artifact.
Affected Systems
The vulnerability affects Rapid7 Velociraptor deployments on Linux platforms. No specific product version information is listed, so all current versions that include the Windows.Sysinternals.SysmonLogForward artifact are potentially impacted.
Risk and Exploitability
The CVSS base score of 5.5 indicates moderate severity, and the EPSS score is not available. The vulnerability is not listed in CISA KEV. An attacker who already has the Investigator role can enable the exploit by collecting the artifact, specifying an arbitrary binary path, and causing the endpoint to execute that binary with the artifact’s elevated privileges. Because the flaw relies on a privilege that many analysts normally possess, the attack vector is likely internal or requires a legitimate user account with this role.
OpenCVE Enrichment