PT-2024-16343 · Rapid7 · Rapid7 Velociraptor Msi Installer

Jean-Baptiste Mesnard-Sense

·

Published

2024-11-07

·

Updated

2024-11-22

·

CVE-2024-10526

CVSS v4.0

8.6

High

VectorAV:L/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/AU:Y/R:U/V:D/RE:L/U:Red
Name of the Vulnerable Software and Affected Versions Rapid7 Velociraptor MSI Installer versions prior to 0.73.3
Description The issue arises from the Rapid7 Velociraptor MSI Installer creating the installation directory with WRITE DACL permission to the BUILTINUsers group. This allows local users who are not administrators to grant themselves the Full Control permission on Velociraptor's files. By modifying Velociraptor's files, local users can subvert the binary and cause the Velociraptor service to execute arbitrary code as the SYSTEM user, or to replace the Velociraptor binary completely.
Recommendations Update to version 0.73.3 to fix the issue. As a temporary workaround, consider restricting access to the installation directory to prevent local users from modifying Velociraptor's files until the update is applied.

Fix

Incorrect Permission

Files Accessible to External Parties

Weakness Enumeration

Related Identifiers

CVE-2024-10526

Affected Products

Rapid7 Velociraptor Msi Installer