Files or Directories Accessible to External Parties
CVE-2024-10526
Summary
Rapid7 Velociraptor MSI Installer versions prior to 0.73.3 suffer from a vulnerability in which the installation directory is created with "WRITE_DACL" permission for the "BUILTIN\Users" group. This allows local non-administrator users to grant themselves Full Control permission on Velociraptor's files. By modifying these files, local users can manipulate the Velociraptor binary, potentially causing the Velociraptor service to execute arbitrary code as the "SYSTEM" user or replace the binary entirely.
- LOW
- LOCAL
- HIGH
- CHANGED
- REQUIRED
- LOW
- HIGH
- HIGH
CWE-552 - Files or Directories Accessible to External Parties
The product makes files or directories accessible to unauthorized actors, even though they should not be.
References
Advisory Timeline
- Published