Unquoted Search Path or Element vulnerability in Grafana Alloy on Windows allows Privilege Escalation from Local User to SYSTEM
This issue affects Alloy: before 1.3.3, from 1.4.0-rc.0 through 1.4.0-rc.1.
                
            Metrics
Affected Vendors & Products
References
        History
                    Thu, 26 Dec 2024 15:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | Microsoft Microsoft windows | |
| CPEs | cpe:2.3:a:grafana:alloy:1.4.0:rc.1:*:*:*:*:*:* | cpe:2.3:a:grafana:alloy:1.4.0:rc0:*:*:*:*:*:* cpe:2.3:a:grafana:alloy:1.4.0:rc1:*:*:*:*:*:* cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* | 
| Vendors & Products | Microsoft Microsoft windows | 
Tue, 01 Oct 2024 19:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| CPEs | cpe:2.3:a:grafana:alloy:1.4.0:rc.0:*:*:*:*:*:* cpe:2.3:a:grafana:alloy:1.4.0:rc.1:*:*:*:*:*:* | 
Thu, 26 Sep 2024 17:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| References |  | 
Thu, 26 Sep 2024 16:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| References |  | 
Wed, 25 Sep 2024 18:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | Grafana Grafana alloy | |
| CPEs | cpe:2.3:a:grafana:alloy:*:*:*:*:*:*:*:* | |
| Vendors & Products | Grafana Grafana alloy | |
| Metrics | ssvc 
 | 
Wed, 25 Sep 2024 17:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | Unquoted Search Path or Element vulnerability in Grafana Alloy on Windows allows Privilege Escalation from Local User to SYSTEM This issue affects Alloy: before 1.3.3, from 1.4.0-rc.0 through 1.4.0-rc.1. | |
| Title | Grafana Alloy on Windows Unquoted service path | |
| Weaknesses | CWE-428 | |
| References |  | |
| Metrics | cvssV3_1 
 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: GRAFANA
Published: 2024-09-25T16:42:09.998Z
Updated: 2024-09-26T16:22:26.037Z
Reserved: 2024-09-18T14:51:37.565Z
Link: CVE-2024-8975
 Vulnrichment
                        Vulnrichment
                    Updated: 2024-09-25T17:42:59.140Z
 NVD
                        NVD
                    Status : Analyzed
Published: 2024-09-25T17:15:19.360
Modified: 2024-12-26T15:00:26.180
Link: CVE-2024-8975
 Redhat
                        Redhat
                    No data.