s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

CVE-2024-4885

📛 CVE Title

WhatsUp Gold GetFileWithoutZip Directory Traversal Remote Code Execution Vulnerability

Description

In WhatsUp Gold versions released before 2023.1.3, an unauthenticated Remote Code Execution vulnerability in Progress WhatsUpGold.  The WhatsUp.ExportUtilities.Export.GetFileWithoutZip allows execution of commands with iisapppool\nmconsole privileges.

Overview

State
PUBLISHED
Assigner (CNA)
ProgressSoftware
CVSS severity
CRITICAL
CVSS score
CVSS 9.8 / 10 9.8 9.8 / 10
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Effective score
9.8 / 10 CRITICAL source: CNA overview
CWE(s)
CWE-22
Reserved
2024-05-14
Published
2024-06-25 21:48 UTC
Last updated
2025-10-22 00:56 UTC
Source
https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2024/4xxx/CVE-2024-4885.json
Linked Threat
CVE-2024-4885 — WhatsUp Gold GetFileWithoutZip Directory Traversal Remote Code Execution Vulnerability

European Union Vulnerability Database ENISA EUVD

ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.

EUVD ID
EUVD-2024-44455
Assigner
ProgressSoftware
Published
Jun 25, 2024, 7:48:15 PM
Updated
Oct 21, 2025, 10:56:21 PM
EUVD base score (CVSS 3.1)
9.8 / 10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EUVD-reported EPSS
94.2700
Vendors
Progress Software Corporation
Products
WhatsUp Gold (2023.1.0 <2023.1.3)
Aliases
GHSA-qcj6-wq2r-c3xh

ENISA description: In WhatsUp Gold versions released before 2023.1.3, an unauthenticated Remote Code Execution vulnerability in Progress WhatsUpGold.  The WhatsUp.ExportUtilities.Export.GetFileWithoutZip allows execution of commands with iisapppool\nmconsole privileges.

EUVD references (2)

Affected products (1)

VendorProductVersionsPlatforms
Progress Software Corporation WhatsUp Gold 2023.1.0 (affected) Windows

Vendor references (2)

References embedded in the original CVE record by the assigning CNA.

Web references (3)

DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.

Indicators (1)

IOCs linked to the auto-promoted Threat row.

TypeValueVirusTotalAttached
domain whatsup.exportutilities.export.getfilewithoutzip no local data 2026-05-18 21:19 UTC

Flagged vendors

    Remediations (17)

    Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.

    • web:learn.microsoft.com

      Learning path Learn how Microsoft supports secure software development as part of a cybersecurity solution - Training Secure software development means integrating security into each phase of your development lifecycle, from requirements analysis to maintenance. Microsoft provides many services that can help you develop more secure code and deploy a more secure application in the cloud. This ...

      2026-08-05 14:27 UTC
    • web:cvefeed.io

      The following table lists the changes that have been made to the CVE-2024-4885 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.

      2026-08-05 14:27 UTC
    • web:www.microsoft.com

      Microsoft's free Security Update Guide Notifications provide links to security-related software updates and notification of re-released security updates. These notifications are sent via email throughout the month as needed. You can choose the type of updates for which you want to be notified: Major ...

      2026-08-05 14:27 UTC
    • web:vulners.com

      CRITICAL: CVE - 2024 -6670, CVE - 2024 -6671 - Multiple SQL Injection vulnerabilities in Progress' WhatsUp Gold. Remember, there was an exploited vulnerability with CVE-2024-4885 for the same product recently.

      2026-08-05 14:27 UTC
    • web:www.oracle.com

      Prior Critical Patch Update and Critical Security Patch Update advisories should be reviewed for information regarding earlier published security patches. Refer to Critical Patch Updates, Critical Security Patch Updates, Security Alerts and Bulletins for information about Oracle Security advisories.

      2026-08-05 14:27 UTC
    • web:www.computerworld.com

      Microsoft says it is considering a patch for a zero-day vulnerability, dubbed YellowKey, that allows attackers with access to a Windows device to bypass Bitlocker encryption protection and read ...

      2026-08-05 14:27 UTC
    • web:catalog.update.microsoft.com

      Welcome to the Microsoft Update Catalog site. We want your feedback! Visit our newsgroup or send us an email to provide us with your thoughts and suggestions. To get started using the site, enter in your search terms in the Search box above or visit our FAQ for search tips. |Newsgroup|Send us your feedback

      2026-08-05 14:27 UTC
    • web:www.linkedin.com

      Microsoft Security Response Center has issued an emergency mitigation for a newly disclosed BitLocker bypass vulnerability known as "YellowKey," after security researchers publicly released ...

      2026-05-22 10:39 UTC
    • web:www.notebookcheck.net

      Microsoft released mitigation steps for YellowKey ( CVE -2026-45585), a BitLocker bypass that grants physical attackers access to encrypted Windows drives.

      2026-05-22 10:39 UTC
    • web:www.securityweek.com

      Microsoft has announced mitigations for CVE -2026-45585, a BitLocker bypass triggered via FsTx in Windows Recovery.

      2026-05-22 10:39 UTC
    • web:www.tomshardware.com

      Microsoft released security update KB5034441 on Patch Tuesday to fix a BitLocker encryption bypass vulnerability affecting Windows 10 users. However, some users are experiencing an update failure ...

      2026-05-22 10:39 UTC
    • web:cybersecuritynews.com

      No patch has been released yet; Microsoft has instead issued a multi-step manual mitigation guide while a formal security update is prepared. Windows BitLocker Security Bypass The vulnerability originates in WinRE's handling of the BootExecute registry value under HKLM\ControlSet001\Control\Session Manager.

      2026-05-22 10:39 UTC
    • web:portal.msrc.microsoft.com

      The Security Update Guide provides information on the latest Microsoft security updates, helping users understand and address potential vulnerabilities effectively.

      2026-05-22 10:39 UTC
    • web:windowsreport.com

      The newly exposed Windows security flaw, dubbed "YellowKey," has become a major headache for Microsoft. After the exploit details leaked publicly alongside a working proof-of-concept, the company has now rushed out official mitigation guidance while it prepares a permanent fix . The vulnerability reportedly targets BitLocker-protected systems and could allow attackers direct access to ...

      2026-05-22 10:39 UTC
    • web:www.bleepingcomputer.com

      Microsoft has disabled a fix for a BitLocker security feature bypass vulnerability due to firmware incompatibility issues that were causing patched Windows devices to go into BitLocker recovery mode.

      2026-05-22 10:39 UTC
    • web:www.computerworld.com

      Each month, the team at Readiness analyzes the latest Patch Tuesday updates from Microsoft and provides detailed, actionable testing guidance. The company's Patch Tuesday release for February ...

      2026-05-22 10:39 UTC
    • web:www.helpnetsecurity.com

      Microsoft is working on a fix for CVE -2026-45585 (aka "Yellowkey"), a vulnerability that can be used to bypass Windows' BitLocker protection.

      2026-05-22 10:39 UTC

    AI Forensic Analysis

    Only Available for Registered Users. Sign in to view.

    Raw JSON

    The full cvelistV5 record. Download as CVE-2024-4885.json.

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:progress:whatsup_gold:2023.1.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "affected",
                "product": "whatsup_gold",
                "vendor": "progress",
                "versions": [
                  {
                    "lessThan": "2023.1.3",
                    "status": "affected",
                    "version": "2023.1.0",
                    "versionType": "semver"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-4885",
                    "options": [
                      {
                        "Exploitation": "active"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-03-03T20:12:05.609998Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              },
              {
                "other": {
                  "content": {
                    "dateAdded": "2025-03-03",
                    "reference": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-4885"
                  },
                  "type": "kev"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-10-21T22:56:21.609Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "government-resource"
                ],
                "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-4885"
              }
            ],
            "timeline": [
              {
                "lang": "en",
                "time": "2025-03-03T00:00:00.000Z",
                "value": "CVE-2024-4885 added to CISA KEV"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-01T20:55:10.084Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "product",
                  "x_transferred"
                ],
                "url": "https://www.progress.com/network-monitoring"
              },
              {
                "tags": [
                  "vendor-advisory",
                  "x_transferred"
                ],
                "url": "https://community.progress.com/s/article/WhatsUp-Gold-Security-Bulletin-June-2024"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "affected",
              "modules": [
                "API Endpoint"
              ],
              "platforms": [
                "Windows"
              ],
              "product": "WhatsUp Gold",
              "vendor": "Progress Software Corporation",
              "versions": [
                {
                  "lessThan": "2023.1.3",
                  "status": "affected",
                  "version": "2023.1.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Sina Kheirkhah (@SinSinology) of Summoning Team (@SummoningTeam) working with Trend Micro Zero Day Initiative"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "In WhatsUp Gold versions released before 2023.1.3,<span style=\"background-color: rgba(161, 189, 217, 0.08);\">&nbsp;an unauthenticated Remote Code Execution vulnerability in Progress WhatsUpGold.&nbsp;&nbsp;T<span style=\"background-color: rgba(161, 189, 217, 0.08);\">he </span><code>\n\nWhatsUp.ExportUtilities.Export.GetFileWithoutZip\n\n</code>\n\n allows execution of commands with </span><code>iisapppool\\nmconsole</code><span style=\"background-color: rgba(161, 189, 217, 0.08);\"> privileges.</span>"
                }
              ],
              "value": "In WhatsUp Gold versions released before 2023.1.3,\u00a0an unauthenticated Remote Code Execution vulnerability in Progress WhatsUpGold.\u00a0\u00a0The \n\nWhatsUp.ExportUtilities.Export.GetFileWithoutZip\n\n\n\n allows execution of commands with iisapppool\\nmconsole privileges."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-113",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-113 API Manipulation"
                }
              ]
            },
            {
              "capecId": "CAPEC-562",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-562 Modify Shared File"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 9.8,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-22",
                  "description": "CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-06-25T19:48:15.268Z",
            "orgId": "f9fea0b6-671e-4eea-8fde-31911902ae05",
            "shortName": "ProgressSoftware"
          },
          "references": [
            {
              "tags": [
                "product"
              ],
              "url": "https://www.progress.com/network-monitoring"
            },
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://community.progress.com/s/article/WhatsUp-Gold-Security-Bulletin-June-2024"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "WhatsUp Gold GetFileWithoutZip Directory Traversal Remote Code Execution Vulnerability",
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f9fea0b6-671e-4eea-8fde-31911902ae05",
        "assignerShortName": "ProgressSoftware",
        "cveId": "CVE-2024-4885",
        "datePublished": "2024-06-25T19:48:15.268Z",
        "dateReserved": "2024-05-14T18:28:11.852Z",
        "dateUpdated": "2025-10-21T22:56:21.609Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }