CVE-2026-7373: Metasploit Pro on Windows: Local Privilege Escalation via OpenSSL Configuration File Loading
Rapid7 Metasploit Pro is vulnerable to a local privilege escalation attack that allows a user to gain SYSTEM level control of a Windows host. When started the metasploitPostgreSQL service would start the postgres.exe child process which would in turn load an OpenSSL configuration file from a static location. This static location would be writable by a pre-existing "vagrant" user, if they already existed on the system. Metasploit does not create local accounts, an Administrator would need to create it. By planting a crafted openssl.cnf file an attacker can trick the high-privilege service into executing arbitrary commands. This effectively permits the unprivileged vagrant user to bypass security controls and achieve a full host compromise under the agent's SYSTEM level access.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7373?
CVE-2026-7373 is classified as a high severity vulnerability due to its potential for local privilege escalation on Windows systems.
How do I fix CVE-2026-7373?
To fix CVE-2026-7373, users should update to the latest version of Rapid7 Metasploit Pro that addresses this vulnerability.
Who is affected by CVE-2026-7373?
CVE-2026-7373 affects users of Rapid7 Metasploit Pro on Windows systems running the PostgreSQL service at startup.
What type of attack does CVE-2026-7373 enable?
CVE-2026-7373 enables a local privilege escalation attack, allowing unauthorized users to gain SYSTEM level control.
When was CVE-2026-7373 disclosed?
CVE-2026-7373 was disclosed as part of ongoing security assessments relating to Rapid7 Metasploit Pro.