CVE-2024-0670

HIGH

Checkmk <2.2.0p23-2.0.0 - Privilege Escalation

Title source: llm

Description

Privilege escalation in windows agent plugin in Checkmk before 2.2.0p23, 2.1.0p40 and 2.0.0 (EOL) allows local user to escalate privileges

Exploits (7)

nomisec WORKING POC 1 stars
by fsoc-ghost-0x · poc
https://github.com/fsoc-ghost-0x/Fsociety-CVE-2024-0670-CheckMK-LPE
nomisec WORKING POC 1 stars
by magicrc · poc
https://github.com/magicrc/CVE-2024-0670
nomisec WORKING POC 1 stars
by elsevar11 · poc
https://github.com/elsevar11/CVE-2024-0670-CheckMK-Agent-Local-Privilege-Escalation-Exploit
nomisec SUSPICIOUS
by Nikopmpm · poc
https://github.com/Nikopmpm/nikopmpm.github.io
nomisec WORKING POC
by zhulin837 · poc
https://github.com/zhulin837/checkmk_cve-2024-0670
nomisec WORKING POC
by tralsesec · poc
https://github.com/tralsesec/CVE-2024-0670
nomisec WORKING POC
by Nikopmpm · poc
https://github.com/Nikopmpm/Fsociety-CVE-2024-0670-CheckMK-LPE

Scores

CVSS v3 8.8
EPSS 0.0012
EPSS Percentile 31.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Classification

CWE
CWE-427
Status published

Affected Products (50)

checkmk/checkmk
checkmk/checkmk < 2.1.0
checkmk/checkmk
checkmk/checkmk
checkmk/checkmk
checkmk/checkmk
checkmk/checkmk
checkmk/checkmk
checkmk/checkmk
checkmk/checkmk
checkmk/checkmk
checkmk/checkmk
checkmk/checkmk
checkmk/checkmk
checkmk/checkmk
... and 35 more

Timeline

Published Mar 11, 2024
Tracked Since Feb 18, 2026