{"id":"CVE-2020-24908","details":"Checkmk before 1.6.0p17 allows local users to obtain SYSTEM privileges via a Trojan horse shell script in the %PROGRAMDATA%\\checkmk\\agent\\local directory.","modified":"2026-07-08T19:02:38.189437Z","published":"2021-02-19T06:15:12.510Z","references":[{"type":"ADVISORY","url":"https://compass-security.com/fileadmin/Research/Advisories/2020-05_CSNC-2020-005_Checkmk_Local_Privilege_Escalation.txt"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/checkmk/checkmk","events":[{"introduced":"0"},{"fixed":"d5ccd5ecc956e665aca80f3c486f7fa46f409424"},{"introduced":"d5ccd5ecc956e665aca80f3c486f7fa46f409424"},{"last_affected":"2c7990e82af4fff30379472838eb5b9ef0ebfa7a"}],"database_specific":{"cpe":["cpe:2.3:a:checkmk:checkmk:*:*:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:1.6.0:-:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:1.6.0:p1:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:1.6.0:p10:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:1.6.0:p11:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:1.6.0:p12:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:1.6.0:p13:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:1.6.0:p14:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:1.6.0:p15:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:1.6.0:p16:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:1.6.0:p2:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:1.6.0:p3:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:1.6.0:p4:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:1.6.0:p5:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:1.6.0:p6:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:1.6.0:p7:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:1.6.0:p8:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:1.6.0:p9:*:*:*:*:*:*"],"extracted_events":[{"introduced":"0"},{"fixed":"1.6.0"},{"introduced":"1.6.0-NA"},{"last_affected":"1.6.0-NA"},{"introduced":"1.6.0-p1"},{"last_affected":"1.6.0-p1"},{"introduced":"1.6.0-p10"},{"last_affected":"1.6.0-p10"},{"introduced":"1.6.0-p11"},{"last_affected":"1.6.0-p11"},{"introduced":"1.6.0-p12"},{"last_affected":"1.6.0-p12"},{"introduced":"1.6.0-p13"},{"last_affected":"1.6.0-p13"},{"introduced":"1.6.0-p14"},{"last_affected":"1.6.0-p14"},{"introduced":"1.6.0-p15"},{"last_affected":"1.6.0-p15"},{"introduced":"1.6.0-p16"},{"last_affected":"1.6.0-p16"},{"introduced":"1.6.0-p2"},{"last_affected":"1.6.0-p2"},{"introduced":"1.6.0-p3"},{"last_affected":"1.6.0-p3"},{"introduced":"1.6.0-p4"},{"last_affected":"1.6.0-p4"},{"introduced":"1.6.0-p5"},{"last_affected":"1.6.0-p5"},{"introduced":"1.6.0-p6"},{"last_affected":"1.6.0-p6"},{"introduced":"1.6.0-p7"},{"last_affected":"1.6.0-p7"},{"introduced":"1.6.0-p8"},{"last_affected":"1.6.0-p8"},{"introduced":"1.6.0-p9"},{"last_affected":"1.6.0-p9"}],"source":["CPE_RANGE","CPE_STRING"]}}],"versions":["1.6.0-NA","1.6.0-p1","1.6.0-p10","1.6.0-p11","1.6.0-p12","1.6.0-p13","1.6.0-p14","1.6.0-p15","1.6.0-p16","1.6.0-p2","1.6.0-p3","1.6.0-p4","1.6.0-p5","1.6.0-p6","1.6.0-p7","1.6.0-p8","1.6.0-p9","v1.6.0p9","v1.6.0p8","v1.6.0p7","v1.6.0p6","v1.6.0p5","v1.6.0p4","v1.6.0p3","v1.6.0p2","v1.6.0p1","v1.6.0","v1.6.0b11","v1.6.0b10","v1.6.0b9","v1.6.0b8","v1.6.0b7","v1.6.0b6","v1.6.0b5","v1.6.0b4","v1.6.0b3","v1.6.0b2","v1.6.0b1","v1.5.0i3","v1.5.0i2","v1.5.0i1","v1.4.0i3","v1.4.0i2","v1.4.0i1","v1.2.5i6","v1.2.5i1","v1.2.3i6","v1.2.3i5","v1.2.3i4","v1.2.1i5","v1.2.0p1","v1.2.0b4","v1.2.0b3","v1.2.0b2","v1.1.13i3","v1.1.13i2","v1.1.11i3","v1.1.11i2","v1.1.11i1","v1.1.10","v1.1.10b2","v1.1.10b1","v1.1.9i9","v1.1.9i8","v1.1.9i7","v1.1.9i5","v1.1.9i4","v1.1.9i3","v1.1.9i1","v1.1.8","v1.1.8b3","v1.1.8b2","v1.1.8b1","v1.1.7i5","v1.1.7i4","v1.1.7i3","v1.1.7i2","v1.1.6","v1.1.6b2","v1.1.4","v1.1.3","v1.1.2","v1.1.0","1.1.0beta17"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-24908.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}