Junglewise Threat Intelligence

CVE-2024-4885: Progress WhatsUp Gold Path Traversal Vulnerability

CVE-2024-4885 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2025-03-03

Technologies: Progress WhatsUp Gold. Vendors: Progress Software Corporation, Progress.

Executive brief

Progress WhatsUp Gold contains a path traversal vulnerability in the WhatsUp.ExportUtilities.Export.GetFileWithoutZip component. An unauthenticated remote attacker can exploit this to execute arbitrary commands with iisapppool\nmconsole privileges.

Affected products

  • Progress Software Corporation WhatsUp Gold versions before 2023.1.3

Timeline

  • 2024-06-25: disclosed: Initial disclosure by Progress Software Corporation
  • 2024-06-25: patched: Vulnerability addressed in version 2023.1.3
  • 2025-03-03: kev added: Added to CISA Known Exploited Vulnerabilities (KEV) catalog
  • 2025-03-03: exploited: Confirmed exploitation in the wild per CISA KEV entry

Related threats