HIGH
Rapid7 Insight Agent Privilege Escalation
Published Mar 17, 2022
7.8
HIGHCVSS 3.1
EPSS 0.48%
Description
Rapid7 Insight Agent versions 3.1.2.38 and earlier suffer from a privilege escalation vulnerability, whereby an attacker can hijack the flow of execution due to an unquoted argument to the runas.exe command used by the ir_agent.exe component, resulting in elevated rights and persistent access to the machine. This issue was fixed in Rapid7 Insight Agent version 3.1.3.80.
Affected products
-
- Version 3.1.2.38StatusaffectedConstraints<=3.1.2.38
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Rapid7 | Insight Agent | n/a |
|
- ≤ 3.1.2.38
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (2)
- https://docs.rapid7.com/release-notes/insightagent/20220225/ x_refsource_CONFIRMRelease NotesVendor Advisory
- https://gist.github.com/n2dez/05d43c616f2b403e84ee55d4d7aab251 x_refsource_MISCExploitThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://docs.rapid7.com/release-notes/insightagent/20220225/ | x_refsource_CONFIRMRelease NotesVendor Advisory | |
| https://gist.github.com/n2dez/05d43c616f2b403e84ee55d4d7aab251 | x_refsource_MISCExploitThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner rapid7
Published Mar 17, 2022
Updated Sep 16, 2024
Reserved Jan 14, 2022
Link CVE-2022-0237
CISA Vulnrichment
Updated n/a