CVE-2022-0237

MEDIUM

Rapid7 Insight Agent <3.1.2.38 - Privilege Escalation

Title source: llm
STIX 2.1

Description

Rapid7 Insight Agent versions 3.1.2.38 and earlier suffer from a privilege escalation vulnerability, whereby an attacker can hijack the flow of execution due to an unquoted argument to the runas.exe command used by the ir_agent.exe component, resulting in elevated rights and persistent access to the machine. This issue was fixed in Rapid7 Insight Agent version 3.1.3.80.

Scores

CVSS v3 4.0
EPSS 0.0006
EPSS Percentile 18.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-428 CWE-264
Status published
Products (1)
rapid7/insight_agent < 3.1.2.38
Published Mar 17, 2022
Tracked Since Feb 18, 2026