CVE-2022-0237

Severity CVSS v4.0:
Pending analysis
Type:
CWE-428 Unquoted Search Path or Element
Publication date:
17/03/2022
Last modified:
24/03/2022

Description

Rapid7 Insight Agent versions 3.1.2.38 and earlier suffer from a privilege escalation vulnerability, whereby an attacker can hijack the flow of execution due to an unquoted argument to the runas.exe command used by the ir_agent.exe component, resulting in elevated rights and persistent access to the machine. This issue was fixed in Rapid7 Insight Agent version 3.1.3.80.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:rapid7:insight_agent:*:*:*:*:*:*:*:* 3.1.2.38 (including)