PT-2025-48748 · Microsoft+1 · Windows+2
Hillel Pinto
·
Published
2025-12-02
·
Updated
2026-04-16
·
CVE-2025-34352
CVSS v4.0
8.5
High
| Vector | AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
JumpCloud Remote Assist for Windows versions prior to 0.317.0
Description
An issue exists in the uninstaller of JumpCloud Remote Assist for Windows, which is executed by the JumpCloud Windows Agent with NT AUTHORITYSYSTEM privileges during update or uninstall operations. The uninstaller performs privileged create, write, execute, and delete actions on predictable files within a user-writable
%TEMP% subdirectory without validating the directory's trust or resetting its Access Control Lists (ACLs). A local, low-privileged attacker can pre-create this directory with weak permissions and use mount-point or symbolic-link redirection to force arbitrary file writes to protected locations, potentially causing a denial of service by overwriting system files. Additionally, an attacker may redirect the DeleteFileW() function to target specific files or folders, enabling arbitrary deletion and local privilege escalation to SYSTEM. This issue potentially affects over 180,000 organizations globally.Recommendations
Update JumpCloud Remote Assist for Windows to version 0.317.0.
Fix
DoS
LPE
Link Following
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Jumpcloud Remote Assist
Jumpcloud Windows Agent
Windows