First published: Fri Apr 11 2025(Updated: )
A code injection vulnerability in the Debian package component of Taegis Endpoint Agent (Linux) versions older than 1.3.10 allows local users arbitrary code execution as root. Redhat-based systems using RPM packages are not affected.
Credit: security-alert@sophos.com
Affected Software | Affected Version | How to fix |
---|---|---|
Sophos Taegis Endpoint Agent | <1.3.10 | |
All of | ||
Sophos Taegis Endpoint Agent | <1.3.10 | |
Debian Linux |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-13861 is classified as a high-severity vulnerability due to its ability to allow arbitrary code execution as root.
To mitigate CVE-2024-13861, upgrade the Taegis Endpoint Agent to version 1.3.10 or later.
CVE-2024-13861 affects local users on Debian systems running Taegis Endpoint Agent versions older than 1.3.10.
No, Redhat-based systems using RPM packages are not affected by CVE-2024-13861.
CVE-2024-13861 is a code injection vulnerability that permits arbitrary code execution.