Skip to main content
CVE Vulnerability Database

CVE-2024-8785: Progress WhatsUp Gold Privilege Escalation

CVE-2024-8785 is a privilege escalation vulnerability in Progress WhatsUp Gold allowing unauthenticated attackers to manipulate registry values via NmAPI.exe. This article covers technical details, affected versions, and mitigation.

Updated:

CVE-2024-8785 Overview

CVE-2024-8785 affects Progress WhatsUp Gold versions released before 2024.0.1. The vulnerability resides in NmAPI.exe, which exposes functionality that allows remote unauthenticated attackers to create or modify registry values under HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Ipswitch\. An attacker can reach this interface over the network without credentials or user interaction. Successful exploitation tampers with configuration data used by the network monitoring product, affecting integrity of the monitoring server. The flaw is tracked under CWE-648: Incorrect Use of Privileged APIs. Progress addressed the issue in WhatsUp Gold 2024.0.1 and documented the fix in its September 2024 Security Bulletin.

Critical Impact

Unauthenticated network attackers can write to Ipswitch registry keys on the WhatsUp Gold server, enabling tampering with monitoring configuration.

Affected Products

  • Progress WhatsUp Gold versions prior to 2024.0.1
  • NmAPI.exe component within affected WhatsUp Gold installations
  • Windows hosts running vulnerable WhatsUp Gold instances exposing the NmAPI service

Discovery Timeline

  • 2024-12-02 - CVE-2024-8785 published to the National Vulnerability Database (NVD)
  • 2024-12-09 - Last updated in NVD database

Technical Details for CVE-2024-8785

Vulnerability Analysis

WhatsUp Gold ships NmAPI.exe, a network-accessible API service used by management components. The service exposes operations that permit creation and modification of registry values under the HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Ipswitch\ path. The exposed registry operations do not require authentication, so any host able to reach the service on the network can invoke them.

The Ipswitch registry hive stores configuration values consumed by WhatsUp Gold services. By writing controlled keys and values into this hive, an attacker influences runtime behavior of the monitoring platform. The advisory does not document direct code execution through this primitive, but registry tampering can disable controls, alter logging, or set up follow-on attacks against the server.

Root Cause

The root cause is improper exposure of a privileged administrative function through a network interface. NmAPI.exe accepts registry write requests without enforcing authentication or authorization on the caller, mapping to [CWE-648]. Registry write capability should be limited to local privileged processes, not remote unauthenticated clients.

Attack Vector

Exploitation occurs over the network against the WhatsUp Gold host where NmAPI.exe is reachable. The attacker requires no credentials and no user interaction. The attacker issues an API call that selects a key path under HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Ipswitch\ and supplies a value to write. Because the call runs in the context of the WhatsUp Gold service, the write succeeds with the service account's privileges.

No public proof-of-concept code is referenced in the CVE record, and verified exploitation code is not available. Technical mechanics should be sourced from the Progress Security Bulletin September 2024 and the WhatsUp Gold 2024.0 Release Notes.

Detection Methods for CVE-2024-8785

Indicators of Compromise

  • Unexpected creation or modification of values under HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Ipswitch\ on the WhatsUp Gold server.
  • Inbound network connections to the NmAPI.exe listener from hosts outside the documented WhatsUp Gold management subnet.
  • Configuration drift in WhatsUp Gold settings not associated with administrator activity or change tickets.

Detection Strategies

  • Monitor Windows registry audit events (Event ID 4657) for writes targeting the Ipswitch key tree on WhatsUp Gold servers.
  • Correlate registry change events with the parent process NmAPI.exe to flag remote-origin modifications.
  • Track process and network telemetry on the WhatsUp Gold host to identify external sources contacting NmAPI service ports.

Monitoring Recommendations

  • Enable Windows registry auditing on HKLM\SOFTWARE\WOW6432Node\Ipswitch\ with a system access control list covering write and create operations.
  • Forward WhatsUp Gold application logs and Windows Security logs to a centralized SIEM for correlation.
  • Alert on any non-administrator account or remote network source triggering writes through NmAPI.exe.

How to Mitigate CVE-2024-8785

Immediate Actions Required

  • Upgrade WhatsUp Gold to version 2024.0.1 or later as directed by the Progress Security Bulletin September 2024.
  • Restrict network access to the WhatsUp Gold server so that only authorized administrative hosts can reach NmAPI.exe.
  • Review the HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Ipswitch\ registry tree for unauthorized values and restore known-good configuration.

Patch Information

Progress fixed CVE-2024-8785 in WhatsUp Gold 2024.0.1. Patch details and download instructions are published in the Progress Security Bulletin September 2024 and the WhatsUp Gold 2024.0 Release Notes. Administrators should apply the upgrade on all WhatsUp Gold servers and verify the version after patching.

Workarounds

  • Block inbound connections to the NmAPI.exe listener at the host firewall except from explicitly trusted management addresses.
  • Place the WhatsUp Gold server in a segmented management network that is not reachable from user or internet-facing zones.
  • Audit and tighten service account permissions used by NmAPI.exe so that compromised configuration cannot escalate impact.
bash
# Example: restrict NmAPI access using Windows Firewall (PowerShell)
New-NetFirewallRule -DisplayName "Restrict WhatsUp Gold NmAPI" \
  -Direction Inbound \
  -Program "C:\Program Files (x86)\Ipswitch\WhatsUp\NmAPI.exe" \
  -RemoteAddress 10.10.20.0/24 \
  -Action Allow

New-NetFirewallRule -DisplayName "Block WhatsUp Gold NmAPI (default)" \
  -Direction Inbound \
  -Program "C:\Program Files (x86)\Ipswitch\WhatsUp\NmAPI.exe" \
  -Action Block

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.