JumpCloud Windows Agent Flaw Enables Local Privilege Escalation
ID: 470b611a-4e00-5744-aafe-664b108167c1
STIX ID: report--470b611a-4e00-5744-aafe-664b108167c1
Feed Name: Infosecurity Magazine (News)
A critical local privilege escalation and DoS vulnerability (CVE-2025-34352) was discovered in JumpCloud Remote Assist for Windows: its uninstaller performs unsafe delete/write/execute operations in user-writable %TEMP% while running as SYSTEM, enabling link-following attacks that can yield persistent SYSTEM access or crash systems. XM Cyber disclosed the issue to JumpCloud, which validated the report and auto-upgraded customers to a patched RAA (0.319.0); organizations are advised to ensure updates are applied.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
