Impact
An uncontrolled search path element in Rapid7 Insight Agent allows a local, low‑privileged user to execute arbitrary code with SYSTEM privileges by planting an executable named "code" in a writable directory that appears early in the machine PATH. This flaw, classified as CWE-427, permits a local user to bypass privilege boundaries and run any code as the highest system account on the host.
Affected Systems
Rapid7 Insight Agent running on Windows is affected. All agent versions are impacted as long as they process assessment content versions 0.0.261.0 or earlier, which are shipped through the Rapid7 Insight Platform regardless of the agent build. The vulnerability is tied to the assessment content rather than the agent code itself.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity vulnerability. EPSS data is not available, and the issue is not listed in the CISA KEV catalog. The likely attack vector is local: a user with write access to a PATH directory preceding the legitimate Visual Studio Code installation can place a malicious executable. Once the agent runs the process as SYSTEM, the attacker achieves full control over the machine. Remote exploitation is not possible; the flaw requires local presence and the ability to write to the specified directory.
OpenCVE Enrichment