Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

N2Dez

#32892of 53,625
7.8Total CVSS
Vulnerabilities · 1
PT-2022-13056
7.8
2022-03-17
Rapid7 · Rapid7 Insight Agent · CVE-2022-0237
**Name of the Vulnerable Software and Affected Versions** Rapid7 Insight Agent versions 3.1.2.38 and earlier **Description** The issue allows an attacker to hijack the flow of execution due to an unquoted argument to the `runas.exe` command used by the `ir agent.exe` component, resulting in elevated rights and persistent access to the machine. **Recommendations** For Rapid7 Insight Agent versions 3.1.2.38 and earlier, update to version 3.1.3.80 to resolve the issue.