CVE-2024-0670

HIGH

Checkmk <2.2.0p23-2.0.0 - Privilege Escalation

Title source: llm

Description

Privilege escalation in windows agent plugin in Checkmk before 2.2.0p23, 2.1.0p40 and 2.0.0 (EOL) allows local user to escalate privileges

Exploits (7)

nomisec WORKING POC 1 stars
by fsoc-ghost-0x · poc
https://github.com/fsoc-ghost-0x/Fsociety-CVE-2024-0670-CheckMK-LPE
nomisec WORKING POC 1 stars
by elsevar11 · poc
https://github.com/elsevar11/CVE-2024-0670-CheckMK-Agent-Local-Privilege-Escalation-Exploit
nomisec WORKING POC 1 stars
by magicrc · poc
https://github.com/magicrc/CVE-2024-0670
nomisec WORKING POC
by Nikopmpm · poc
https://github.com/Nikopmpm/Fsociety-CVE-2024-0670-CheckMK-LPE
nomisec WORKING POC
by tralsesec · poc
https://github.com/tralsesec/CVE-2024-0670
nomisec SUSPICIOUS
by Nikopmpm · poc
https://github.com/Nikopmpm/nikopmpm.github.io
nomisec WORKING POC
by zhulin837 · poc
https://github.com/zhulin837/checkmk_cve-2024-0670

Scores

CVSS v3 8.8
EPSS 0.0015
EPSS Percentile 35.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-427
Status published
Products (2)
checkmk/checkmk 2.1.0 (49 CPE variants)
checkmk/checkmk 2.2.0
Published Mar 11, 2024
Tracked Since Feb 18, 2026