CVE-2024-10526
HIGHRapid7 Velociraptor MSI Installer <0.73.3 - Privilege Escalation
Title source: llmDescription
Rapid7 Velociraptor MSI Installer versions below 0.73.3 suffer from a vulnerability whereby it creates the installation directory with WRITE_DACL permission to the BUILTIN\\Users group. This allows local users who are not administrators to grant themselves the Full Control permission on Velociraptor's files. By modifying Velociraptor's files, local users can subvert the binary and cause the Velociraptor service to execute arbitrary code as the SYSTEM user, or to replace the Velociraptor binary completely. This issue is fixed in version 0.73.3.
Scores
CVSS v4
8.6
EPSS
0.0002
EPSS Percentile
6.2%
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/AU:Y/R:U/V:D/RE:L/U:Red
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-552
CWE-732
Status
published
Products (1)
Rapid7/Velociraptor
<0.73.2
Published
Nov 07, 2024
Tracked Since
Feb 18, 2026