PT-2023-16105 · Unknown · Velociraptor

Paul Alkemade

·

Published

2023-01-18

·

Updated

2024-08-20

·

CVE-2023-0242

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Velociraptor versions prior to 0.6.7-5
Description The issue allows a low privilege user to overwrite files on the server, including Velociraptor configuration files, due to the VQL copy() function not checking for permission to write files. To exploit this, an attacker must have a Velociraptor user account at a low privilege level and be able to log into the GUI and create a notebook where they can run the VQL query invoking the copy() VQL function.
Recommendations For Velociraptor versions prior to 0.6.7-5, update to version 0.6.7-5 or later to resolve the issue. As a temporary workaround, consider restricting access to the copy() function for low privilege users until a patch is applied. Additionally, limit the ability of low privilege users to create notebooks and run VQL queries that invoke the copy() function.

Fix

Improper Privilege Management

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2023-0242
GHSA-G5VM-525Q-R66C
GO-2023-1527
OPENSUSE-SU-2024:12916-1

Affected Products

Velociraptor