5.5

CVE-2026-78413

Velociraptor privilege escalation via SysmonLogForward client monitoring artifact

Velociraptor allows collection of VQL queries packaged into Artifacts from endpoints. These artifacts can be used to do anything and usually run with elevated permissions. To limit access to some dangerous artifact, Velociraptor allows for those to require high permissions like EXECVE to launch.

The `Windows.Sysinternals.SysmonLogForward` is a monitoring artifact used to forward sysmon events to the server. The artifact allows the user to specify an arbitrary binary path as a parameter, and did not enforce an additional required permission, allowing users with COLLECT_CLIENT permissions (normally given by the "Investigator" role) to collect it from endpoints and run a different binary program than the installed sysmon binary.
To successfully exploit this vulnerability the user must already have access to collect artifacts from the endpoint (i.e. have the COLLECT_CLIENT given typically by the "Investigator" role).
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerRapid7
≫
Produkt Velociraptor
Default Statusunaffected
Version 0
Version < 0.77.3
Status affected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.16% 0.042
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Rapid7 5.5 1.3 3.7
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:L
CWE-276 Incorrect Default Permissions

During installation, installed file permissions are set to allow anyone to modify those files.

http://docs.velociraptor.app/announcements/advisories/cve-2026-78413
https://github.com/Velocidex/velociraptor/commit/7906c82fad728010f2fe1d0555b99dbaba3ce88f