CVE-2024-8975
NixOS vulnerability analysis and mitigation

Overview

CVE-2024-8975 is an Unquoted Search Path or Element vulnerability affecting Grafana Alloy on Windows systems. The vulnerability was discovered on September 17, 2024, and publicly disclosed on September 25, 2024. It affects Grafana Alloy versions before 1.3.3 and versions 1.4.0-rc.0 through 1.4.0-rc.1 (Grafana Advisory, NVD).

Technical details

The vulnerability stems from the Grafana Alloy Windows installer not properly enclosing service executable paths in quotes. This is classified as CWE-428 (Unquoted Search Path or Element). The vulnerability has received a CVSS 3.1 base score of 7.8 HIGH (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) from NIST and 7.3 HIGH (AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H) from Grafana Labs (NVD).

Impact

The vulnerability allows privilege escalation from a local user to SYSTEM privileges on Windows machines with Grafana Alloy installed. An attacker could exploit this by adding an executable named c:\Program.exe, which Windows services would then run with elevated privileges instead of Grafana Alloy (Grafana Blog).

Mitigation and workarounds

Grafana Labs recommends completely removing the Grafana Alloy installation and performing a clean install, as a simple update will not resolve the issue. Alternatively, users can manually add double quotes to the registry entry at Computer\HKEYLOCALMACHINE\SYSTEM\CurrentControlSet\Services\Alloy\ImagePath. Fixed versions are available in Grafana Alloy v1.4.1 and v1.3.4 (Grafana Blog).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-48606HIGH7.8
  • NixOSNixOS
  • android
NoNoDec 08, 2025
CVE-2025-48625HIGH7
  • NixOSNixOS
  • android
NoNoDec 08, 2025
CVE-2025-48608MEDIUM5.5
  • NixOSNixOS
  • android
NoNoDec 08, 2025
CVE-2025-48569MEDIUM5.5
  • NixOSNixOS
  • android
NoNoDec 08, 2025
CVE-2025-65799MEDIUM4.3
  • NixOSNixOS
  • memos
NoYesDec 08, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management