CVE-2024-5016: WhatsUp Gold OnMessage Deserialization of Untrusted Data Remote Code Execution Vulnerability
In WhatsUp Gold versions released before 2023.1.3, Distributed Edition installations can be exploited by using a deserialization tool to achieve a Remote Code Execution as SYSTEM. The vulnerability exists in the main message processing routines NmDistributed.DistributedServiceBehavior.OnMessage for server and NmDistributed.DistributedClient.OnMessage for clients.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WhatsUp Gold Distributed Editionto a version that resolves this vulnerability.Fixed in 2023.1.3
Event History
Frequently Asked Questions
What is the severity of CVE-2024-5016?
CVE-2024-5016 is rated as critical due to its potential for Remote Code Execution as SYSTEM.
How do I fix CVE-2024-5016?
To mitigate CVE-2024-5016, upgrade WhatsUp Gold to version 2023.1.3 or later.
What versions of WhatsUp Gold are affected by CVE-2024-5016?
CVE-2024-5016 affects WhatsUp Gold versions prior to 2023.1.3, including version 23.1.0.
What is the potential impact of CVE-2024-5016?
The impact of CVE-2024-5016 includes unauthorized remote code execution, which can compromise the integrity of the system.
Is CVE-2024-5016 specific to certain installations of WhatsUp Gold?
Yes, CVE-2024-5016 specifically affects installations of WhatsUp Gold in distributed edition configurations.