Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2024-12902

CVE-2024-12902: ANCHOR Default Credentials Vulnerability

CVE-2024-12902 is a default credentials vulnerability in ANCHOR from Global Wisdom Software that allows attackers to gain unauthorized access to high-privilege Windows service accounts. This article covers technical details, impact, and mitigations.

Updated:

CVE-2024-12902 Overview

CVE-2024-12902 affects ANCHOR from Global Wisdom Software, an integrated product distributed as a Windows virtual machine appliance. The underlying Windows operating system ships with high-privilege service accounts configured with default passwords. Attackers who reach the virtual machine over the network can authenticate remotely using these known credentials and gain administrative control.

The issue is categorized under [CWE-1392] Use of Default Credentials. Taiwan CERT/CC published coordinated advisories describing the exposure and the vendor response.

Critical Impact

Successful exploitation grants attackers full administrative access to the ANCHOR virtual machine, exposing confidentiality, integrity, and availability of the appliance and any data it processes.

Affected Products

  • Global Wisdom Software ANCHOR (integrated Windows virtual machine appliance)
  • Underlying Windows OS service accounts shipped with the appliance
  • Deployments where default credentials were not rotated after installation

Discovery Timeline

  • 2024-12-23 - CVE-2024-12902 published to the National Vulnerability Database
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2024-12902

Vulnerability Analysis

ANCHOR is delivered as a pre-configured Windows virtual machine. During image preparation, the vendor created high-privilege service accounts on the guest OS and assigned them static, default passwords. These credentials are identical across every deployment of the appliance.

Because the credentials are documented or discoverable, any attacker with network reachability to the virtual machine can authenticate against Windows remote services such as Remote Desktop Protocol (RDP), Server Message Block (SMB), or Windows Management Instrumentation (WMI). Authentication as a high-privilege service account bypasses application-layer controls entirely.

The CVSS vector indicates local attack context, but the practical exploitation path is remote authentication to the guest OS using known credentials. Once authenticated, an attacker inherits the full privileges of the compromised service account, which the advisory describes as high-privilege.

Root Cause

The root cause is the use of hardcoded default passwords on privileged Windows accounts within the shipped appliance image. The product does not enforce a mandatory password change on first boot, so operators who deploy ANCHOR without manually rotating credentials remain exposed indefinitely.

Attack Vector

An attacker with access to the network segment hosting the ANCHOR virtual machine enumerates exposed Windows services and attempts authentication using the default account names and passwords. Successful login yields interactive or programmatic access at the privilege level of the service account. From there, the attacker can pivot into hosted applications, exfiltrate data, install persistence, or disrupt operations. No exploit code is required; the attack relies entirely on credential reuse. See the Taiwan CERT Security Advisory (English) for vendor-coordinated details.

Detection Methods for CVE-2024-12902

Indicators of Compromise

  • Successful interactive or network logons to ANCHOR virtual machines using vendor default account names
  • Unexpected RDP, SMB, or WinRM sessions originating from non-administrative hosts
  • New local accounts, scheduled tasks, or services created on the ANCHOR VM shortly after authentication events

Detection Strategies

  • Review Windows Security event logs on the ANCHOR guest for Event ID 4624 (successful logon) tied to service accounts, especially logon types 3 (network), 10 (RemoteInteractive), and 5 (service).
  • Alert on any authentication attempt using the vendor default account names documented in the Taiwan CERT advisory.
  • Correlate authentication events with source IP addresses outside the expected administrative subnet.

Monitoring Recommendations

  • Forward Windows event logs from ANCHOR appliances to a centralized log platform for long-term retention and correlation.
  • Baseline normal administrative access patterns and alert on deviations in source, time-of-day, or session duration.
  • Continuously scan the appliance for weak or default credentials as part of routine identity hygiene reviews.

How to Mitigate CVE-2024-12902

Immediate Actions Required

  • Change the passwords of all high-privilege Windows service accounts on every deployed ANCHOR virtual machine to unique, strong values.
  • Restrict network access to the ANCHOR VM's management services (RDP, SMB, WinRM) using host firewalls or network segmentation.
  • Audit recent authentication logs for signs of prior unauthorized access with default credentials.

Patch Information

Global Wisdom Software has published guidance through Taiwan CERT/CC. Refer to the Taiwan CERT Security Advisory (English) and the Taiwan CERT Security Advisory (Traditional Chinese) for the vendor's remediation instructions and any updated appliance images.

Workarounds

  • Isolate the ANCHOR virtual machine on a dedicated management VLAN accessible only from trusted administrative hosts.
  • Disable unused Windows remote access services on the appliance to reduce the attack surface.
  • Enforce account lockout and multi-factor authentication for any account permitted to access the appliance where technically supported.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.