Floragasse 7 – 5th floor, 1040 Vienna
Subscribe to our Newsletter

News

SBA Security Advisory – Checkmk Agent Privilege Escalation via Insecure Temporary Files (CVE-2025-32919)

Vulnerability Overview

The `win_license` plugin as included in Checkmk agent for Windows versions before 2.4.0p13, 2.3.0p38 and 2.2.0p46, as well as since version 2.1.0b2 and 2.0.0p28 allows low privileged users to escalate privileges to Local System due to insecure use of a temporary folder.

  • Type of Vulnerability: Privilege Escalation
  • Fixed in Version: 2.4.0p13, 2.3.0p38, 2.2.0p46
  • CVE ID: CVE-2025-32919
  • CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
  • CVSS Base Score: 8.8 (High)

Recommended Countermeasure

We recommend updating to Checkmk version 2.4.0p13, 2.3.0p38, 2.2.0p46 or later, and make sure that all hosts use the updated plugin version.

Link

Full Security Advisory

Credits

Lisa Gnedt (SBA Research)