Known Exploited Vulnerabilities CVE-2024-4885

Progress WhatsUp Gold contains a path traversal vulnerability that allows an unauthenticated attacker to achieve remote code execution.

Mappings

Capability ID Capability Description Mapping Type ATT&CK ID ATT&CK Name Notes
CVE-2024-4885 Progress WhatsUp Gold Path Traversal Vulnerability exploitation_technique T1068 Exploitation for Privilege Escalation
Comments
By sending a crafted payload to a vulnerable WhatsUp Gold server, an attacker can conduct a path traversal attack and write malicious files onto the server. This leads to high-privileged remote code execution.
References
CVE-2024-4885 Progress WhatsUp Gold Path Traversal Vulnerability primary_impact T1059 Command and Scripting Interpreter
Comments
By sending a crafted payload to a vulnerable WhatsUp Gold server, an attacker can conduct a path traversal attack and write malicious files onto the server. This leads to high-privileged remote code execution.
References