CVE-2024-28241: GlPI-Agent MSI package installation doesn't update folder security profile when using non default installation folder
The GLPI Agent is a generic management agent. Prior to version 1.7.2, a local user can modify GLPI-Agent code or used DLLs to modify agent logic and even gain higher privileges. Users should upgrade to GLPI-Agent 1.7.2 to receive a patch. As a workaround, use the default installation folder which involves installed folder is automatically secured by the system.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-28241?
CVE-2024-28241 has been rated as a medium severity vulnerability due to the potential for local users to modify the GLPI Agent code.
How do I fix CVE-2024-28241?
To fix CVE-2024-28241, users should upgrade to GLPI-Agent version 1.7.2 or later.
Who is affected by CVE-2024-28241?
CVE-2024-28241 affects all versions of GLPI-Agent prior to 1.7.2.
What kind of exploitation is possible with CVE-2024-28241?
An attacker with local access could modify GLPI-Agent code or DLLs to change agent functionality or escalate privileges.
Is there a workaround for CVE-2024-28241?
As a temporary measure, users can utilize the default installation settings until they can upgrade.