CVE-2024-28240

The GLPI Agent is a generic management agent. A vulnerability that only affects GLPI-Agent installed on windows via MSI packaging can allow a local user to cause denial of agent service by replacing GLPI server url with a wrong url or disabling the service. Additionally, in the case the Deploy task is installed, a local malicious user can trigger privilege escalation configuring a malicious server providing its own deploy task payload. GLPI-Agent 1.7.2 contains a patch for this issue. As a workaround, edit GLPI-Agent related key under `HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall` and add `SystemComponent` DWORD value setting it to `1` to hide GLPI-Agent from installed applications.
Configurations

Configuration 1 (hide)

cpe:2.3:a:glpi-project:glpi_agent:*:*:*:*:*:*:*:*

History

22 Jan 2025, 20:17

Type Values Removed Values Added
First Time Glpi-project
Glpi-project glpi Agent
References () https://github.com/glpi-project/glpi-agent/commit/41bbb1169e899bd15350a9e2fdbf9269a3b7a14f - () https://github.com/glpi-project/glpi-agent/commit/41bbb1169e899bd15350a9e2fdbf9269a3b7a14f - Patch
References () https://github.com/glpi-project/glpi-agent/security/advisories/GHSA-hx3x-mmqg-h3jp - () https://github.com/glpi-project/glpi-agent/security/advisories/GHSA-hx3x-mmqg-h3jp - Vendor Advisory
CWE NVD-CWE-noinfo
CPE cpe:2.3:a:glpi-project:glpi_agent:*:*:*:*:*:*:*:*

Information

Published : 2024-04-25 17:15

Updated : 2025-01-22 20:17


NVD link : CVE-2024-28240

Mitre link : CVE-2024-28240

CVE.ORG link : CVE-2024-28240


JSON object : View

Products Affected

glpi-project

  • glpi_agent
CWE
CWE-20

Improper Input Validation

NVD-CWE-noinfo