CVE-2024-10526: Rapid7 Velociraptor Local Privilege Escalation In Windows Velociraptor Service
Rapid7 Velociraptor MSI Installer versions below 0.73.3 suffer from a vulnerability whereby it creates the installation directory with WRITEDACL permission to the BUILTIN\\Users group. This allows local users who are not administrators to grant themselves the Full Control permission on Velociraptor's files. By modifying Velociraptor's files, local users can subvert the binary and cause the Velociraptor service to execute arbitrary code as the SYSTEM user, or to replace the Velociraptor binary completely. This issue is fixed in version 0.73.3.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-10526?
CVE-2024-10526 is considered a high-severity vulnerability due to its potential to allow unauthorized users to gain Full Control permissions.
How do I fix CVE-2024-10526?
To fix CVE-2024-10526, upgrade Rapid7 Velociraptor to version 0.73.3 or later, which addresses this permission vulnerability.
Which versions of Rapid7 Velociraptor are affected by CVE-2024-10526?
Rapid7 Velociraptor versions below 0.73.3 are affected by CVE-2024-10526.
What is the impact of CVE-2024-10526?
The impact of CVE-2024-10526 is that non-administrative local users can exploit the vulnerability to elevate their permissions on the system.
Is there a workaround for CVE-2024-10526?
There is no official workaround for CVE-2024-10526; upgrading to the fixed version is the recommended solution.