CyberRota Analysis
AI-GeneratedRapid7 InsightVM, Nexpose, and the Insight Agent are vulnerable due to a lack of file ownership validation when executing discovered executables during authenticated assessments. This flaw allows local low-privileged users to execute arbitrary code with the privileges of the scan credential or even as root/SYSTEM, posing a significant security risk. Organizations using these products should prioritize patching to mitigate potential exploitation.
Original NVD Description
Rapid7 InsightVM, Nexpose, and the Insight Agent execute discovered executables during authenticated assessment without validating file ownership, allowing a local low-privileged user to run code as the scan credential (Scan Engine) or as root/SYSTEM (Insight Agent). Fixed in Scan Engine content 1.1.3935 and Insight Agent content component 0.0.245.0.