CVE-2024-13861: Code Injection
Published Apr 11, 2025
·Updated
A code injection vulnerability in the Debian package component of Taegis Endpoint Agent (Linux) versions older than 1.3.10 allows local users arbitrary code execution as root. Redhat-based systems using RPM packages are not affected.
Affected Software
3 affected components
Taegis Endpoint Agent<1.3.10
All of the following
Sophos Taegis Endpoint Agent Linux<1.3.10
Debian Debian Linux
Event History
Apr 11, 2025
CVE Published
via MITRE·12:41 PM
Data Sourced
via MITRE·12:41 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-13861?
CVE-2024-13861 is classified as a high-severity vulnerability due to its ability to allow arbitrary code execution as root.
2
How do I fix CVE-2024-13861?
To mitigate CVE-2024-13861, upgrade the Taegis Endpoint Agent to version 1.3.10 or later.
3
Who is affected by CVE-2024-13861?
CVE-2024-13861 affects local users on Debian systems running Taegis Endpoint Agent versions older than 1.3.10.
4
Are Redhat-based systems affected by CVE-2024-13861?
No, Redhat-based systems using RPM packages are not affected by CVE-2024-13861.
5
What type of vulnerability is CVE-2024-13861?
CVE-2024-13861 is a code injection vulnerability that permits arbitrary code execution.