PT-2024-36062 · Kolide+1 · Kolide Agent+2
Bryan Alexander
·
Published
2024-12-03
·
Updated
2024-12-11
·
CVE-2024-54131
CVSS v4.0
7.3
High
| Vector | AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions:
Kolide Agent versions 1.5.3 through 1.12.2
Description:
An implementation bug in the Kolide Agent allows for local privilege escalation to the SYSTEM user on Windows 10 and 11. The bug was introduced when the launcher started storing upgraded binaries in the ProgramData directory, resulting in incorrect default permissions. A malicious actor with access to the local Windows device can place an arbitrary DLL into the osqueryd process's search path, which may be executed when osqueryd performs a WMI query, allowing the attacker to escalate their privileges to SYSTEM.
Recommendations:
For versions 1.5.3 through 1.12.2, update to version 1.12.3 to resolve the issue.
As a temporary workaround, consider restricting access to the ProgramData directory to minimize the risk of exploitation.
Avoid using the osqueryd process until the issue is resolved.
Restrict the use of the
launcher package until the update to version 1.12.3 is applied.Exploit
Fix
Incorrect Default Permissions
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Kolide Agent
Windows 10
Windows 11