标题:Rapid7 Insight Agent 在 Windows 上因不受控的搜索路径元素导致本地提权漏洞 漏洞描述: Rapid7 Insight Agent 在 Windows 平台上的 InsightVM 评估内容中存在一处不受控的搜索路径元素(Uncontrolled Search Path Element)漏洞。该漏洞允许本地低权限用户通过植入一个可被执行文件,利用机器 PATH 环境变量中的路径解析机制,以 SYSTEM 权限执行任意代码。 在版本号为 0.0.261.0 或更低的评估内容中,包含一个
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Rapid7 | Insight Agent | 0 ~ 0.0.261.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-19072 | 9.9 CRITICAL | Velociraptor Investigator reaches SuperUser via hunt EffectivePrincipal |
| CVE-2026-77798 | 6.5 MEDIUM | Velociraptor Authenticated Denial of Service |
| CVE-2026-77797 | 3.6 LOW | Velociraptor Prefetch parser out of bounds |
No comments yet