CVE-2024-8996

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Sep 25, 2024
Updated: Oct 1, 2024
CWE ID 428

Summary

CVE-2024-8996 is a newly disclosed vulnerability affecting the Grafana Agent in Flow mode on Windows systems. This issue involves an Unquoted Search Path or Element vulnerability, which can allow a local user to escalate privileges and gain SYSTEM level access. The vulnerability impacts Grafana Agent Flow before version 0.43.2. This weakness could potentially enable an attacker to execute arbitrary code and take complete control of the affected Windows system. Organizations using the Grafana Agent in Flow mode on Windows should urgently update to the latest version to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share