Description
Rapid7 Insight Agent versions 3.1.2.38 and earlier suffer from a privilege escalation vulnerability, whereby an attacker can hijack the flow of execution due to an unquoted argument to the runas.exe command used by the ir_agent.exe component, resulting in elevated rights and persistent access to the machine. This issue was fixed in Rapid7 Insight Agent version 3.1.3.80.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-15432 | Rapid7 Insight Agent versions 3.1.2.38 and earlier suffer from a privilege escalation vulnerability, whereby an attacker can hijack the flow of execution due to an unquoted argument to the runas.exe command used by the ir_agent.exe component, resulting in elevated rights and persistent access to the machine. This issue was fixed in Rapid7 Insight Agent version 3.1.3.80. |
References
History
No history.
Status: PUBLISHED
Assigner: rapid7
Published:
Updated: 2024-09-16T20:01:39.262Z
Reserved: 2022-01-14T00:00:00.000Z
Link: CVE-2022-0237
No data.
Status : Modified
Published: 2022-03-17T23:15:07.523
Modified: 2024-11-21T06:38:12.433
Link: CVE-2022-0237
No data.
OpenCVE Enrichment
No data.
EUVD