← voltar
CVE-2024-5016highCWE-502

WhatsUp Gold OnMessage Deserialization of Untrusted Data Remote Code Execution Vulnerability

26Vexday Risk Score

Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.

ssvc Trackcvss 7.2epss 22%
probabilidade de exploração
22%top 3% das CVEs
exploração observada
nãonenhuma fonte reporta
In WhatsUp Gold versions released before 2023.1.3, Distributed Edition installations can be exploited by using a deserialization tool to achieve a Remote Code Execution as SYSTEM.  The vulnerability exists in the main message processing routines NmDistributed.DistributedServiceBehavior.OnMessage for server and NmDistributed.DistributedClient.OnMessage for clients.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H