CVE-2024-9858
Severity CVSS v4.0:
MEDIUM
Type:
Unavailable / Other
Publication date:
16/10/2024
Last modified:
30/07/2025
Description
There exists an insecure default user permission in Google Cloud Migrate to containers from version 1.1.0 to 1.2.2 Windows installs. A local "m2cuser" was greated with administrator privileges. This posed a security risk if the "analyze" or "generate" commands were interrupted or skipping the action to delete the local user “m2cuser”. We recommend upgrading to 1.2.3 or beyond
Impact
Base Score 4.0
5.90
Severity 4.0
MEDIUM
Base Score 3.x
7.80
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:google:migrate_to_containers:*:*:*:*:*:*:*:* | 1.1.0 (including) | 1.2.3 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



