Security Advisory

CVE-2024-4885

9.8
CRITICAL

Vulnerability Description

In WhatsUp Gold versions released before 2023.1.3, an unauthenticated Remote Code Execution vulnerability in Progress WhatsUpGold.  The WhatsUp.ExportUtilities.Export.GetFileWithoutZip allows execution of commands with iisapppool\nmconsole privileges.
Published Date June 25, 2024
Official Source NIST NVD Advisory