### [CVE-2024-0670](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-0670) ![](https://img.shields.io/static/v1?label=Product&message=Checkmk&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=2.2.0%3C%202.2.0p23%20&color=brighgreen) ![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-427%20Uncontrolled%20Search%20Path%20Element&color=brighgreen) ### Description Privilege escalation in windows agent plugin in Checkmk before 2.2.0p23, 2.1.0p40 and 2.0.0 (EOL) allows local user to escalate privileges ### POC #### Reference - http://seclists.org/fulldisclosure/2024/Mar/29 - https://checkmk.com/werk/16361 #### Github - https://github.com/fkie-cad/nvd-json-data-feeds