PT-2026-106061 · Unknown · Velociraptor
CVSS v3.1
5.5
Medium
| Vector | AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Velociraptor (affected versions not specified)
Description
Velociraptor uses Artifacts to package VQL queries for collection from endpoints, which typically execute with elevated permissions. To restrict dangerous operations, certain artifacts require high-level permissions such as EXECVE. The
Windows.Sysinternals.SysmonLogForward monitoring artifact, designed to forward sysmon events to the server, allows users to specify an arbitrary binary path as a parameter. Because it fails to enforce the necessary additional permissions, users with COLLECT CLIENT permissions (typically assigned to the Investigator role) can execute an arbitrary binary program on the endpoint instead of the intended sysmon binary.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
LPE
Incorrect Default Permissions
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Velociraptor