CVE-2024-4885
KEVmoderateUnauthenticated Path Traversal RCE in Progress WhatsUp Gold
CISA: Progress WhatsUp Gold Path Traversal Vulnerability
CVE-2024-4885 is an unauthenticated path traversal vulnerability (CWE-22) in the WhatsUp.ExportUtilities.Export.GetFileWithoutZip function of Progress WhatsUp Gold, a network monitoring platform. An attacker can send a crafted request to the affected export/file-retrieval functionality to traverse outside the intended directory, which leads to execution of commands on the server. Successful exploitation yields remote code execution running with the privileges of the iisapppool\mconsole application pool identity, giving control of the WhatsUp Gold monitoring server and, potentially, a foothold in the network. All WhatsUp Gold versions released before 2023.1.3 are affected, meaning any organization running an unpatched on-premises deployment is exposed, especially if the web interface is reachable from untrusted networks. The flaw is being actively exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2025-03-03, and its 99.3% EPSS probability reflects very high expected exploitation; no public PoC is known, though headlines indicate exploitation followed shortly after a proof-of-concept for this WhatsUp Gold flaw.
What to do: Upgrade WhatsUp Gold to version 2023.1.3 or later, per Progress's advisories (which shipped patches for this and several related WhatsUp Gold flaws). Until patched, restrict access to the WhatsUp Gold web interface to trusted networks and review logs for unexpected requests to the export utility; federal agencies must apply vendor mitigations or follow BOD 22-01 guidance by the KEV due date. Because the flaw is unauthenticated and exploited in the wild, treat any internet-facing, unpatched instance as compromised until verified.
| progress whatsup gold | all versions released before 2023.1.3 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
In WhatsUp Gold versions released before 2023.1.3, an unauthenticated Remote Code Execution vulnerability in Progress WhatsUpGold. The WhatsUp.ExportUtilities.Export.GetFileWithoutZip allows execution of commands with iisapppool\nmconsole privileges.
- Affected
- Progress WhatsUp Gold
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- progress
- Products
- whatsup gold
- Weakness
- CWE-22
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H