PT-2024-36062 · Kolide+1 · Kolide Agent+2

Bryan Alexander

·

Published

2024-12-03

·

Updated

2024-12-11

·

CVE-2024-54131

CVSS v4.0

7.3

High

VectorAV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions: Kolide Agent versions 1.5.3 through 1.12.2
Description: An implementation bug in the Kolide Agent allows for local privilege escalation to the SYSTEM user on Windows 10 and 11. The bug was introduced when the launcher started storing upgraded binaries in the ProgramData directory, resulting in incorrect default permissions. A malicious actor with access to the local Windows device can place an arbitrary DLL into the osqueryd process's search path, which may be executed when osqueryd performs a WMI query, allowing the attacker to escalate their privileges to SYSTEM.
Recommendations: For versions 1.5.3 through 1.12.2, update to version 1.12.3 to resolve the issue. As a temporary workaround, consider restricting access to the ProgramData directory to minimize the risk of exploitation. Avoid using the osqueryd process until the issue is resolved. Restrict the use of the launcher package until the update to version 1.12.3 is applied.

Exploit

Fix

Incorrect Default Permissions

Weakness Enumeration

Related Identifiers

CVE-2024-54131
GHSA-66Q9-2RVX-QFJ5
GO-2024-3308
OPENSUSE-SU-2024:14567-1

Affected Products

Kolide Agent
Windows 10
Windows 11