QID 375435

QID 375435: Checkmk Local Privilege Escalation Vulnerability

Checkmk is an IT infrastructure monitoring software. It is consists of a management server querying the clients and of an agent installed on the monitored systems.

CVE-2020-24908: Windows agent service sets correct access rights in ProgramData directory
Affected Versions:
Checkmk before 1.6.0p17.

QID Detection Logic (Authenticated) :
This QID will detect the version of Checkmk from installed path.

On Successful exploitation could allow a user on a systems monitored by Checkmk to escalate its privileges to become a local administrator.

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as High - 7.2 severity.
  • Solution
    Upgrade Checkmk to 1.6.0p17 or above Vendor has released fix to address these vulnerabilities. Refer to FG-IR-19-179
    Vendor References

    CVEs related to QID 375435

    Software Advisories
    Advisory ID Software Component Link
    11460 URL Logo checkmk.com/werk/11460