CVE-2024-8996: Grafana Agent Flow on Windows Unquoted service path
Unquoted Search Path or Element vulnerability in Grafana Agent (Flow mode) on Windows allows Privilege Escalation from Local User to SYSTEM This issue affects Agent Flow: before 0.43.2
Other sources
Unquoted Search Path or Element vulnerability in Grafana Agent (Flow mode) on Windows allows Privilege Escalation from Local User to SYSTEM. This issue affects Agent Flow before 0.43.3.
— GitHub
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-8996?
CVE-2024-8996 has a high severity rating as it allows privilege escalation from a local user to SYSTEM on Windows systems running affected versions of Grafana Agent.
How do I fix CVE-2024-8996?
To mitigate CVE-2024-8996, upgrade Grafana Agent to version 0.43.3 or later.
Which versions of Grafana Agent are affected by CVE-2024-8996?
CVE-2024-8996 affects Grafana Agent versions before 0.43.2.
What operating system is affected by CVE-2024-8996?
CVE-2024-8996 affects the Windows operating system when used with vulnerable versions of Grafana Agent.
Can local users exploit CVE-2024-8996?
Yes, local users can exploit CVE-2024-8996 to escalate their privileges to SYSTEM on Windows.