Executive brief
Rapid7 Insight Agent is a software component used to monitor and collect security data from corporate endpoints. A security issue on Windows systems allows any user with local access to the computer to read sensitive certificate files, including private keys. This could allow an unauthorized person to impersonate the security agent, potentially compromising the integrity of security monitoring and data collection.
Technical details
Rapid7 Insight Agent for Windows (versions prior to 4.1.0.2) incorrectly assigns permissions to installer certificate files located in the 'bootstrap/common/ssl' directory. Specifically, the 'client.key' file and other certificates are assigned read and execute permissions for standard users (CWE-732). A locally authenticated attacker with low privileges can access these files to extract agent identity material. This could be leveraged to impersonate the agent or interfere with its communication with the Insight platform. The issue is resolved in Insight Agent version 4.1.0.2.
Affected products
- Rapid7 Insight Agent versions up to (excluding) 4.1.0.2
Timeline
- 2026-04-10: disclosed
- 2026-04-10: advisory: Rapid7 released version 4.1.0.2 to address the issue.