CVE-2024-10526 HIGH

CVE-2024-10526: Rapid7 Velociraptor Local Privilege Escalation In Windows Velociraptor Service

Vendor Rapid7
Product Velociraptor
Weakness CWE-552 · Files accessible externally
Published November 7, 2024
Last update November 7, 2024

CVSS base score

8.6/10
Attack vector Local
Attack complexity Low
Privileges required Low
User interaction
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/AU:Y/R:U/V:D/RE:L/U:Red

What the vulnerability does

01Description

Rapid7 Velociraptor MSI Installer versions below 0.73.3 suffer from a vulnerability whereby it creates the installation directory with WRITE_DACL permission to the BUILTIN\\Users group. This allows local users who are not administrators to grant themselves the Full Control permission on Velociraptor's files. By modifying Velociraptor's files, local users can subvert the binary and cause the Velociraptor service to execute arbitrary code as the SYSTEM user, or to replace the Velociraptor binary completely.  This issue is fixed in version 0.73.3.

Key dates

02Disclosure timeline

November 7, 2024 CVE published
November 7, 2024 Record updated