Security Advisory
CVE-2024-4885
9.8
CRITICAL
Vulnerability Description
In WhatsUp Gold versions released before 2023.1.3, an unauthenticated Remote Code Execution vulnerability in Progress WhatsUpGold. The
WhatsUp.ExportUtilities.Export.GetFileWithoutZip
allows execution of commands with iisapppool\nmconsole privileges.
Published Date
June 25, 2024
Official Source
NIST NVD Advisory