CVE-2024-0394: Rapid7 Minerva Armor Privilege Escalation
Rapid7 Minerva Armor versions below 4.5.5 suffer from a privilege escalation vulnerability whereby an authenticated attacker can elevate privileges and execute arbitrary code with SYSTEM privilege. The vulnerability is caused by the product's implementation of OpenSSL'sOPENSSLDIR parameter where it is set to a path accessible to low-privileged users. The vulnerability has been remediated and fixed in version 4.5.5.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-0394?
CVE-2024-0394 is rated as a high severity vulnerability due to its potential for privilege escalation and arbitrary code execution with SYSTEM privileges.
How do I fix CVE-2024-0394?
To fix CVE-2024-0394, upgrade Rapid7 Minerva Armor to version 4.5.5 or later.
Who is affected by CVE-2024-0394?
CVE-2024-0394 affects users of Rapid7 Minerva Armor versions below 4.5.5.
What causes the vulnerability in CVE-2024-0394?
The vulnerability in CVE-2024-0394 is caused by the implementation of OpenSSL's 'OPENSSLDIR' in Rapid7 Minerva Armor.
Can an unprivileged user exploit CVE-2024-0394?
Yes, an authenticated attacker with regular user privileges can exploit CVE-2024-0394 to elevate their privileges.