PT-2024-28664 · Veertu · Veertu Anka Build
Kpc
+1
·
Published
2024-10-03
·
Updated
2025-09-04
·
CVE-2024-39755
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Veertu Anka Build version 1.42.0
Description
A privilege escalation vulnerability exists in the node update functionality of Veertu Anka Build. The vulnerability occurs during Anka node agent update, allowing a low privilege user to trigger the issue. A specially crafted PKG file can lead to the execution of privileged operations. An attacker can make an unauthenticated HTTP request to trigger this vulnerability. The issue is due to a Time-of-Check-to-Time-of-Use (TOCTOU) attack, where the downloaded package can be replaced with a malicious one before installation.
Recommendations
For Veertu Anka Build version 1.42.0, consider disabling the node update functionality until a patch is available to prevent exploitation. Restrict access to the Anka node agent update process to minimize the risk of privilege escalation. Avoid using specially crafted PKG files in the update process. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
LPE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Veertu Anka Build