PT-2024-16343 · Rapid7 · Rapid7 Velociraptor Msi Installer
Jean-Baptiste Mesnard-Sense
·
Published
2024-11-07
·
Updated
2024-11-22
·
CVE-2024-10526
CVSS v4.0
8.6
High
| Vector | AV:L/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/AU:Y/R:U/V:D/RE:L/U:Red |
Name of the Vulnerable Software and Affected Versions
Rapid7 Velociraptor MSI Installer versions prior to 0.73.3
Description
The issue arises from the Rapid7 Velociraptor MSI Installer creating the installation directory with WRITE DACL permission to the BUILTINUsers group. This allows local users who are not administrators to grant themselves the Full Control permission on Velociraptor's files. By modifying Velociraptor's files, local users can subvert the binary and cause the Velociraptor service to execute arbitrary code as the SYSTEM user, or to replace the Velociraptor binary completely.
Recommendations
Update to version 0.73.3 to fix the issue.
As a temporary workaround, consider restricting access to the installation directory to prevent local users from modifying Velociraptor's files until the update is applied.
Fix
Incorrect Permission
Files Accessible to External Parties
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Rapid7 Velociraptor Msi Installer