EUVD-2024-44455
In WhatsUp Gold versions released before 2023.1.3, an unauthenticated Remote Code Execution vulnerability in Progress WhatsUpGold. The WhatsUp.ExportUtilities.Export.GetFileWithoutZip allows execution of commands with iisapppool\nmconsole privileges.
- EUVD state
- Present in the current official mapping
- Known exploitation
- Recorded by ENISA since 3 Mar 2025. Evidence sources: cisa_kev.
- ENISA score
- 9.8 · CVSS 3.1
- Advisory evidence
- 1 linked advisory record
Only statements that explicitly mention a fix, patch, update, workaround or mitigation are shown here.
- csaf_ncscnl · NCSC-2024-0268Kwetsbaarheden verholpen in Progress WhatsUp Gold
