Description
Use of an insecure temporary directory in the Windows License plugin for the Checkmk Windows Agent allows Privilege Escalation. This issue affects Checkmk: from 2.4.0 before 2.4.0p13, from 2.3.0 before 2.3.0p38, from 2.2.0 before 2.2.0p46, and all versions of 2.1.0 (EOL).
Problem types
CWE-427: Uncontrolled Search Path Element
Product status
2.4.0 before 2.4.0p13
2.3.0 before 2.3.0p38
2.2.0 before 2.2.0p46
2.1.0
Credits
Lisa Gnedt (SBA Research)