CVE-2024-4885: Progress WhatsUp Gold Path Traversal Vulnerability
In WhatsUp Gold versions released before 2023.1.3, an unauthenticated Remote Code Execution vulnerability in Progress WhatsUpGold. The
WhatsUp.ExportUtilities.Export.GetFileWithoutZip
allows execution of commands with iisapppool\nmconsole privileges.
Other sources
Progress WhatsUp Gold contains a path traversal vulnerability that allows an unauthenticated attacker to achieve remote code execution.
— CISA
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-4885?
CVE-2024-4885 is categorized as a critical vulnerability due to its ability to allow unauthenticated remote code execution.
How do I fix CVE-2024-4885?
To remediate CVE-2024-4885, upgrade WhatsUp Gold to version 2023.1.3 or later.
What are the affected versions for CVE-2024-4885?
CVE-2024-4885 affects WhatsUp Gold versions prior to 2023.1.3.
What privileges are exploited in CVE-2024-4885?
CVE-2024-4885 exploits the iisapppool\nmconsole privileges to execute commands.
Is CVE-2024-4885 currently being exploited?
Yes, CVE-2024-4885 is reported to be under active exploitation.