ZeroHour

CVE-2024-4885

KEVmoderate

Unauthenticated Path Traversal RCE in Progress WhatsUp Gold

CISA: Progress WhatsUp Gold Path Traversal Vulnerability

CVSS 3.1
9.8 critical
EPSS
99%p100
Published
()
KEV added
AI analysis

CVE-2024-4885 is an unauthenticated path traversal vulnerability (CWE-22) in the WhatsUp.ExportUtilities.Export.GetFileWithoutZip function of Progress WhatsUp Gold, a network monitoring platform. An attacker can send a crafted request to the affected export/file-retrieval functionality to traverse outside the intended directory, which leads to execution of commands on the server. Successful exploitation yields remote code execution running with the privileges of the iisapppool\mconsole application pool identity, giving control of the WhatsUp Gold monitoring server and, potentially, a foothold in the network. All WhatsUp Gold versions released before 2023.1.3 are affected, meaning any organization running an unpatched on-premises deployment is exposed, especially if the web interface is reachable from untrusted networks. The flaw is being actively exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2025-03-03, and its 99.3% EPSS probability reflects very high expected exploitation; no public PoC is known, though headlines indicate exploitation followed shortly after a proof-of-concept for this WhatsUp Gold flaw.

What to do: Upgrade WhatsUp Gold to version 2023.1.3 or later, per Progress's advisories (which shipped patches for this and several related WhatsUp Gold flaws). Until patched, restrict access to the WhatsUp Gold web interface to trusted networks and review logs for unexpected requests to the export utility; federal agencies must apply vendor mitigations or follow BOD 22-01 guidance by the KEV due date. Because the flaw is unauthenticated and exploited in the wild, treat any internet-facing, unpatched instance as compromised until verified.

Affected
progress whatsup goldall versions released before 2023.1.3
Estimated exposure
moderatelow thousands of internet-exposed WhatsUp Gold servers; total on-prem deployments plausibly in the tens of thousands — WhatsUp Gold is an on-premises enterprise network monitoring product with a long-established install base, and public internet scans of its web interface typically show a few thousand exposed instances, while many more run internally.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

In WhatsUp Gold versions released before 2023.1.3, an unauthenticated Remote Code Execution vulnerability in Progress WhatsUpGold. The WhatsUp.ExportUtilities.Export.GetFileWithoutZip allows execution of commands with iisapppool\nmconsole privileges.

CISA Known Exploited Vulnerability
Affected
Progress WhatsUp Gold
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
progress
Products
whatsup gold
Weakness
CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news