Controlup develops a monitoring and management platform for virtual desktop infrastructure and endpoint environments, with vulnerabilities concentrated in its core agent and server components. The observed weakness classes recur around command-injection risks, unquoted search paths, and hard-coded credentials, reflecting the administrative and system-level access that endpoint management agents require. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Controlup over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-45913HIGH A hardcoded key in ControlUp Real-Time Agent (cuAgent.exe) before 8.2.5 may allow a potential attacker to run OS commands via a WCF channel. | Jan 4, 2022 | 7.2 | 23 | NO | NO |
CVE-2022-27905HIGH In ControlUp Real-Time Agent before 8.6, an unquoted path can result in privilege escalation. An attacker would require write permissions to the root level of the OS drive (C:\) to | Apr 27, 2022 | 7.2 | 22 | NO | NO |
CVE-2021-45912HIGH An unauthenticated Named Pipe channel in Controlup Real-Time Agent (cuAgent.exe) before 8.5 potentially allows an attacker to run OS commands via the ProcessActionRequest WCF metho | Jan 4, 2022 | 7.8 | 20 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Controlup.
Media articles that mention a CVE ID that affects a product developed by Controlup — matched by CVE ID, not by vendor name.