logo

JumpCloud Windows Agent Flaw Enables Local Privilege Escalation

ID: 470b611a-4e00-5744-aafe-664b108167c1

STIX ID: report--470b611a-4e00-5744-aafe-664b108167c1

Feed Name: Infosecurity Magazine (News)

Threat Score
75/100

Date Published: 2025-12-16

Date Updated: 2026-04-22

...
...

A critical local privilege escalation and DoS vulnerability (CVE-2025-34352) was discovered in JumpCloud Remote Assist for Windows: its uninstaller performs unsafe delete/write/execute operations in user-writable %TEMP% while running as SYSTEM, enabling link-following attacks that can yield persistent SYSTEM access or crash systems. XM Cyber disclosed the issue to JumpCloud, which validated the report and auto-upgraded customers to a patched RAA (0.319.0); organizations are advised to ensure updates are applied.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.