CVE-2024-28240
GLPI Agent vulnerability analysis and mitigation

Overview

The GLPI Agent, a generic management agent, contains a vulnerability (CVE-2024-28240) that affects installations on Windows systems via MSI packaging. The vulnerability was discovered and disclosed on April 25, 2024, affecting all versions prior to 1.7.2. This security issue specifically impacts the Windows MSI package installation of GLPI-Agent (GitHub Advisory).

Technical details

The vulnerability has been assigned a CVSS v3.1 base score of 7.8 (HIGH) with the vector string CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H. The issue stems from improper input validation (CWE-20) in the MSI packaging implementation, allowing local users to modify critical agent configurations (NVD).

Impact

The vulnerability can lead to two primary impacts: first, a denial of agent service can be achieved by replacing the GLPI server URL with an incorrect URL or by disabling the service entirely; second, in cases where the Deploy task is installed, privilege escalation is possible through the configuration of a malicious server that provides malicious deploy task payloads (GitHub Advisory).

Exploitability

The vulnerability requires local access and low privileges to exploit. While user interaction is not required according to the NVD scoring, the GitHub advisory indicates that some user interaction may be needed. The attack complexity is considered low, making it relatively straightforward to exploit for attackers with local access (NVD).

Mitigation and workarounds

The vulnerability has been patched in GLPI-Agent version 1.7.2. As a workaround, administrators can edit the GLPI-Agent related key under HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall and add SystemComponent DWORD value setting it to 1 to hide GLPI-Agent from installed applications. Additionally, MSI support can be disabled by setting the per-machine DisableMSI policy to 2 (GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related GLPI Agent vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2024-28241HIGH7.8
  • GLPI Agent logoGLPI Agent
  • cpe:2.3:a:glpi-project:glpi_agent
NoYesApr 25, 2024
CVE-2024-28240HIGH7.8
  • GLPI Agent logoGLPI Agent
  • cpe:2.3:a:glpi-project:glpi_agent
NoYesApr 25, 2024
CVE-2023-34254HIGH7.2
  • GLPI Agent logoGLPI Agent
  • glpi
NoYesJun 23, 2023

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management