CVE-2024-8785
WhatsUp Gold vulnerability analysis and mitigation

Overview

CVE-2024-8785 is a critical vulnerability affecting Progress WhatsUp Gold versions prior to 24.0.1, discovered and disclosed on September 24, 2024. The vulnerability allows a remote unauthenticated attacker to leverage NmAPI.exe to create or change existing registry values in the registry path HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Ipswitch\ (Tenable Research, NVD).

Technical details

The vulnerability exists in NmAPI.exe, which is a Windows Communication Foundation (WCF) application. It implements an UpdateFailoverRegistryValues operation contract that can be invoked by an unauthenticated remote attacker via a netTcpBinding at net.tcp://:9643. The vulnerability has received a CVSS v3.1 base score of 9.8 (Critical) from Progress Software Corporation, with a vector string of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H (Tenable Research).

Impact

The vulnerability allows attackers to modify registry values under HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Ipswitch. Specifically, attackers can change the InstallDir registry value to point to a UNC path they control, which can lead to remote code execution when the Ipswitch Service Control Manager service restarts (Tenable Research).

Exploitability

An exploit for this vulnerability exists and has been acknowledged by Progress Software. The vulnerability can be exploited remotely without authentication. According to Censys, there were approximately 1,219 exposed WhatsUp Gold instances online at the time of their analysis, with 51% of these instances geolocated in Brazil (Censys).

Mitigation and workarounds

Users are advised to upgrade to WhatsUp Gold version 24.0.1 or later to address this vulnerability (Tenable Research, NVD).

Additional resources


SourceThis report was generated using AI

Related WhatsUp Gold vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-65941HIGH8.8
  • WhatsUp Gold logoWhatsUp Gold
  • cpe:2.3:a:progress:whatsup_gold
NoYesAug 12, 2026
CVE-2026-65937HIGH8
  • WhatsUp Gold logoWhatsUp Gold
  • cpe:2.3:a:progress:whatsup_gold
NoYesAug 12, 2026
CVE-2026-65940MEDIUM6.8
  • WhatsUp Gold logoWhatsUp Gold
  • cpe:2.3:a:progress:whatsup_gold
NoYesAug 12, 2026
CVE-2026-65939MEDIUM6.8
  • WhatsUp Gold logoWhatsUp Gold
  • cpe:2.3:a:progress:whatsup_gold
NoYesAug 12, 2026
CVE-2026-65938MEDIUM4.3
  • WhatsUp Gold logoWhatsUp Gold
  • cpe:2.3:a:progress:whatsup_gold
NoYesAug 12, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management