Executive brief
Netdata's Windows agent installer can be abused during repair operations to execute arbitrary commands with SYSTEM-level privileges. An attacker with access to a user's local machine can plant malicious PowerShell commands that execute with elevated rights when an administrator initiates an MSI repair, leading to full system compromise and potential installation of ransomware or persistent malware.
Technical details
During MSI repair, powershell.exe is launched as SYSTEM without the -NoProfile flag, causing it to load the user's PowerShell profile from %USERPROFILE%\Documents\WindowsPowerShell\Microsoft.PowerShell_profile.ps1. A low-privileged attacker can pre-populate this profile with arbitrary commands that execute with SYSTEM privileges when a repair is triggered. This is a local privilege escalation requiring user interaction (repair initiation) by an administrator.
Affected products
- Netdata Windows Agent 2.0.0 through 2.10.3
Timeline
- 2026-09-22: disclosed
- 2026-06-17: patched: Fixed in version 2.10.4