CVE-2026-83598
Netdata is an open source observability tool. From rom 2.0.0 until 2.10.4, during Netdata Windows Agent MSI repair, powershell.exe runs as SYSTEM without -NoProfile and loads %USERPROFILE%\Documents\WindowsPowerShell\Microsoft.PowerShell_profile.ps1 from the low-privileged user who initiated repair. Commands placed in that profile before repair therefore execute with SYSTEM privileges. This vulnerability is fixed in 2.10.4.
Fraqueza
Netdata is an open source observability tool. From rom 2.0.0 until 2.10.4, during Netdata Windows Agent MSI repair, powershell.exe runs as SYSTEM without -NoProfile and loads %USERPROFILE%\Documents\WindowsPowerShell\Microsoft.PowerShell_profile.ps1 from the low-privileged user who initiated repair. Commands placed in that profile before repair therefore execute with SYSTEM privileges. This vulnerability is fixed in 2.10.4.
Referências
- https://github.com/netdata/netdata/commit/d762782697623a98b51b4e41f7fe2d12404f0662
- https://github.com/netdata/netdata/pull/22751
- https://github.com/netdata/netdata/releases/tag/v2.10.4
- https://github.com/netdata/netdata/security/advisories/GHSA-8hxv-2mg6-ggw5
- https://github.com/netdata/netdata/security/advisories/GHSA-8hxv-2mg6-ggw5
Encontre a falha antes de um atacante.
Entre com o GitHub e rode sua primeira auditoria em menos de um minuto. O plano gratuito não exige cartão de crédito.