CVE-2024-9858

Severity CVSS v4.0:
MEDIUM
Type:
Unavailable / Other
Publication date:
16/10/2024
Last modified:
30/07/2025

Description

There exists an insecure default user permission in Google Cloud Migrate to containers from version 1.1.0 to 1.2.2 Windows installs. A local "m2cuser" was greated with administrator privileges. This posed a security risk if the "analyze" or "generate" commands were interrupted or skipping the action to delete the local user “m2cuser”. We recommend upgrading to 1.2.3 or beyond

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:google:migrate_to_containers:*:*:*:*:*:*:*:* 1.1.0 (including) 1.2.3 (excluding)