logo

Exploit released for critical WhatsUp Gold RCE flaw, patch now

ID: 94e522f7-a90b-59bd-afeb-e6904041ebff

STIX ID: report--94e522f7-a90b-59bd-afeb-e6904041ebff

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2024-12-03

Date Updated: 2026-03-27

Author: Bill Toulas

...
...

A public proof-of-concept for CVE-2024-8785 — a critical (CVSS 9.8) unauthenticated RCE in WhatsUp Gold's NmAPI.exe — has been published. An attacker can change registry settings to point the product to attacker-controlled UNC shares, causing the service to load and execute remote files; Progress released fixes in version 24.0.1 and administrators are urged to patch immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.