CVE-2024-4885
Description
In WhatsUp Gold versions released before 2023.1.3, an unauthenticated Remote Code Execution vulnerability in Progress WhatsUpGold. The
WhatsUp.ExportUtilities.Export.GetFileWithoutZip
allows execution of commands with iisapppool\nmconsole privileges.
Summary dbcve.org
An unauthenticated Remote Code Execution vulnerability exists in Progress WhatsUp Gold's ExportUtilities.Export.GetFileWithoutZip function in versions prior to 2023.1.3. Attackers can execute arbitrary commands with iisapppool\nmconsole (IIS application pool) privileges without any authentication, achieving remote code execution on the affected system.
Mitigation
Upgrade WhatsUp Gold to version 2023.1.3 or later to patch the vulnerability. Given the unauthenticated nature and critical CVSS score, prioritize this upgrade immediately and restrict network exposure to the application until patched.