Executive brief
Progress WhatsUp Gold contains a path traversal vulnerability in the WhatsUp.ExportUtilities.Export.GetFileWithoutZip component. An unauthenticated remote attacker can exploit this to execute arbitrary commands with iisapppool\nmconsole privileges.
Affected products
- Progress Software Corporation WhatsUp Gold versions before 2023.1.3
Timeline
- 2024-06-25: disclosed: Initial disclosure by Progress Software Corporation
- 2024-06-25: patched: Vulnerability addressed in version 2023.1.3
- 2025-03-03: kev added: Added to CISA Known Exploited Vulnerabilities (KEV) catalog
- 2025-03-03: exploited: Confirmed exploitation in the wild per CISA KEV entry