ZDI-CAN-24004: ZDI-24-886: Progress Software WhatsUp Gold SetAdminPassword Improper Access Control Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Progress Software WhatsUp Gold. An attacker must first obtain the ability to execute low-privileged code on the target system or send an HTTP request from a local machine in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.4. The following CVEs are assigned: CVE-2024-5009.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-24004?
The severity of ZDI-CAN-24004 is critical due to its ability to escalate privileges on affected installations.
How do I fix ZDI-CAN-24004?
To fix ZDI-CAN-24004, you should apply the latest security patches provided by Progress Software for WhatsUp Gold.
Who is affected by ZDI-CAN-24004?
ZDI-CAN-24004 affects all installations of Progress Software WhatsUp Gold that have not been patched.
What type of attack does ZDI-CAN-24004 enable?
ZDI-CAN-24004 enables local attackers to escalate privileges after executing low-privileged code.
Can ZDI-CAN-24004 be exploited remotely?
No, ZDI-CAN-24004 requires local access or an HTTP request from a local machine to exploit.