CVE-2024-8975 is an Unquoted Search Path or Element vulnerability in Grafana Alloy on Windows, affecting versions before 1.3.3 and 1.4.0-rc.0 through 1.4.0-rc.1. This flaw allows a local user to escalate privileges to SYSTEM. With a CVSS score of 7.8 (High), it has a low attack complexity and no user interaction required, enabling high impact on confidentiality, integrity, and availability. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.3.3CPE matchmatch criteria | cpe:2.3:a:grafana:alloy:*:*:*:*:*:*:*:* | ||
1.4.0CPE matchmatch criteria | cpe:2.3:a:grafana:alloy:1.4.0:rc0:*:*:*:*:*:* | ||
1.4.0CPE matchmatch criteria | cpe:2.3:a:grafana:alloy:1.4.0:rc1:*:*:*:*:*:* | ||
>= 0, < 1.3.3CPE match | cpe:2.3:a:grafana:alloy:*:*:*:*:*:*:*:* | ||
>= 1.4.0-rc.0, <= 1.4.0-rc.1CPE match | cpe:2.3:a:grafana:alloy:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Grafana Alloy on Windows has Unquoted Search Path or Element vulnerability
Sep 25, 2024Privilege Escalation in Service Path in Grafana Alloy
Sep 25, 2024Privilege Escalation in Service Path in Grafana Alloy
Sep 25, 2024Privilege Escalation in Service Path in Grafana Alloy
Sep 25, 2024Privilege Escalation in Service Path in Grafana Alloy
Sep 25, 2024Privilege Escalation in Service Path in Grafana Alloy
Sep 25, 2024Privilege Escalation in Service Path in Grafana Alloy
Sep 25, 2024