A privilege escalation vulnerability exists in the Windows agent plugin of Checkmk versions prior to 2.2.0p23, 2.1.0p40, and 2.0.0 (EOL). This vulnerability allows a local user to escalate their privileges on the affected system. The specific mechanism of escalation is not detailed, but it is likely due to improper privilege management or access control within the agent plugin.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
7 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository is a small, focused local privilege-escalation exploit for CVE-2024-0670 affecting the CheckMK Windows Agent MSI repair process. It contains one PowerShell exploit script and one README with usage guidance. The exploit is not part of a larger framework. The main script, CVE-2024-0670-NanoCorp.ps1, accepts optional parameters for a PID range and the username/password to create. It builds a batch payload that writes whoami output to C:\programdata\pwn2, creates a user with net user, and adds that user to the administrators group. The script then enumerates the Windows Installer registry under HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products to find a CheckMK MSI package by matching DisplayName and extracting LocalPackage. If no MSI is found, it exits. To exploit the vulnerability, the script pre-creates many predictable temporary command files named C:\Windows\Temp\cmk_all_<PID>_<CTR>.cmd across a configurable PID range. It marks them read-only and then launches msiexec.exe with /fa against the located MSI package, causing a repair operation. The intended effect is that the vulnerable repair workflow executes one of the attacker-planted .cmd files as SYSTEM, resulting in arbitrary command execution and privilege escalation. After the repair completes, the script reports the created credentials and attempts cleanup of the planted files. Capabilities: local privilege escalation to SYSTEM context via MSI repair abuse, arbitrary command execution through a planted batch file, creation of a new administrative user, and basic execution verification via whoami output. The payload is hardcoded and basic rather than modular, so OPERATIONAL is the best maturity fit. Notable code quality issue: the cleanup/status section appears malformed in the provided script (Write-Host string quoting is broken around "Cleaning up;"), but the exploit intent and core logic are still clear.
Repository contains a single PowerShell exploit (exploit.ps1) plus README and MIT license. It is an operational PoC for CVE-2024-0670 (CheckMK Windows Agent LPE). The script: (1) builds a batch payload that runs a netcat reverse shell (nc64.exe -e cmd.exe) to hardcoded LHOST/LPORT; (2) queries the Windows Installer registry under HKLM\...\UserData\S-1-5-18\Products\*\InstallProperties to find an installed product whose DisplayName matches '*mk*' and extracts its LocalPackage MSI path; (3) mass-creates predictable .cmd files in C:\Windows\Temp named cmk_all_<num>_<ctr>.cmd across a configurable numeric range (MinPID..MaxPID) and two counters (0..1), attempting to mark them read-only; (4) triggers a silent MSI repair via msiexec.exe /fa "<LocalPackage>" /qn and waits. The intended effect is that the MSI repair process (running elevated) executes one of the pre-seeded predictable command files, yielding code execution as NT AUTHORITY\SYSTEM and a reverse shell back to the attacker.
This repository contains a C++ exploit for CVE-2024-0670, targeting the CheckMK Agent on Windows 10 and 11. The main file, 'Fsociety-CVE-2024-0670.cpp', implements a local privilege escalation (LPE) exploit that leverages a vulnerability in the CheckMK Agent's file handling to gain SYSTEM-level access. The exploit provides a user-friendly interface, supports command execution as SYSTEM, and can optionally use Netcat (nc.exe) for reverse shell functionality. It also includes a persistence module to maintain access after reboots. The exploit interacts with several fingerprintable file paths, such as 'C:\Windows\Temp\nc.exe' (Netcat binary), 'C:\Windows\Temp\Fsociety-Command-Output.txt' (for command output), and references a marker file 'fsociety00.dat'. The repository is structured with a single C++ code file, a README with usage instructions, and a license. The exploit is operational and suitable for post-exploitation scenarios where local code execution is possible.
This repository contains a single C++ exploit (Fsociety-CVE-2024-0670.cpp) targeting CVE-2024-0670, a local privilege escalation vulnerability in the CheckMK Agent for Windows. The exploit abuses a logic flaw in the agent's handling of temporary plugin wrapper scripts in C:\Windows\Temp. By pre-creating malicious .cmd files with specific names and setting them as read-only, the attacker causes the agent (running as SYSTEM) to execute attacker-controlled code. The exploit provides options for spawning a SYSTEM shell, executing arbitrary commands, and installing a persistent backdoor. It requires local access to the target and the ability to trigger a service restart. The README.md provides a detailed technical breakdown, usage instructions, and attack flow. No network endpoints are hardcoded, but the exploit can use Netcat (nc.exe) for reverse shells if present. The code is operational and weaponized for real-world use.
This repository provides a proof-of-concept (PoC) exploit for CVE-2024-0670, a local privilege escalation vulnerability in the CheckMK Windows Agent by Tribe29. The exploit leverages the fact that during an MSI repair operation, the CheckMK agent executes files from the C:\Windows\Temp directory with SYSTEM privileges. The attacker, as a low-privileged user, seeds this directory with batch files containing a Netcat reverse shell payload, then triggers an MSI repair to execute the payload as SYSTEM. The repository contains three files: a detailed README with usage instructions, a C# program (RunasCs.cs) that allows running commands as another user (used to launch the exploit as SYSTEM), and a PowerShell script (exploit.ps1) that automates the exploitation process. The exploit requires the attacker to download necessary binaries (RunasCs.exe, nc.exe, exploit.ps1) to the target, and to have a Netcat listener running. The main attack vector is local privilege escalation, and the exploit is a PoC with a batch reverse shell payload. Key fingerprintable endpoints include the C:\Windows\Temp directory, the registry path for MSI packages, and the use of Netcat for the reverse shell.
This repository contains a PowerShell proof-of-concept exploit (CVE-2024-0670.ps1) and a README.md describing the vulnerability and usage. The exploit targets a local privilege escalation vulnerability in the CheckMK Agent for Windows (CVE-2024-0670). The PowerShell script automates the process of creating a large number of read-only .cmd files in C:\Windows\Temp, each containing a user-specified command. It locates the CheckMK Agent's MSI installer via the Windows registry, then triggers a repair operation using msiexec.exe. When the agent attempts to create a temporary file that already exists as read-only, it fails to overwrite it but still executes the file as SYSTEM, allowing the attacker's command to run with elevated privileges. The exploit is local, requires write access to C:\Windows\Temp, and is customizable via script parameters. The README provides background, usage instructions, and an example demonstrating SYSTEM-level command execution. No network endpoints are involved; all actions are performed locally on the target system.
This repository contains an exploit for CVE-2024-0670 targeting Check MK installations on Windows. The exploit consists of a PowerShell script (zh.ps1) and a README.md with usage instructions. The README describes how to set up a web server to host the exploit script and required binaries (nc64.exe for reverse shell, RunasCs.exe for privilege escalation), and how to use PowerShell's Invoke-WebRequest to download them to the target. The zh.ps1 script searches the Windows registry for SYSTEM-owned Check MK MSI files, seeds malicious batch files in the Temp directory, and triggers a repair of the MSI package, which can result in code execution as SYSTEM. The payload attempts to establish a reverse shell to the attacker's host and port using nc64.exe. The exploit requires the attacker to have the ability to execute PowerShell scripts and upload/download files on the target. The repository is operational and provides a working exploit chain, but is not part of a larger framework.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.