CVE-2024-41799
Last modified
CVE-2024-41799 is a critical-severity vulnerability rated 9.9/10 on the CVSS scale. tgstation-server is a production scale tool for BYOND server management. Prior to 6.8.0, low permission users using the "Set .dme Path" privilege could potentially set malicious .dme files existing on the host machine to be compiled and executed. EPSS estimates a 1.21% chance of exploitation in the next 30 days.
Description
tgstation-server is a production scale tool for BYOND server management. Prior to 6.8.0, low permission users using the "Set .dme Path" privilege could potentially set malicious .dme files existing on the host machine to be compiled and executed. These .dme files could be uploaded via tgstation-server (requiring a separate, isolated privilege) or some other means. A server configured to execute in BYOND's trusted security level (requiring a third separate, isolated privilege OR being set by another user) could lead to this escalating into remote code execution via BYOND's shell() proc. The ability to execute this kind of attack is a known side effect of having privileged TGS users, but normally requires multiple privileges with known weaknesses. This vector is not intentional as it does not require control over the where deployment code is sourced from and _may_ not require remote write access to an instance's `Configuration` directory. This problem is fixed in versions 6.8.0 and above.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Tgstation13 | Tgstation-Server | >= 4.0.0, < 6.8.0 |
References
- https://github.com/tgstation/tgstation-server/pull/1835Issue Tracking
- https://github.com/tgstation/tgstation-server/pull/1835Issue Tracking
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-41799?
How severe is CVE-2024-41799?
How do I fix CVE-2024-41799?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-41793A vulnerability has been identified in SENTRON 7KT PAC1260 D…7.5
- CVE-2024-41794A vulnerability has been identified in SENTRON 7KT PAC1260 D…9.8
- CVE-2024-41795A vulnerability has been identified in SENTRON 7KT PAC1260 D…6.9
- CVE-2024-41796A vulnerability has been identified in SENTRON 7KT PAC1260 D…6.9
- CVE-2024-41797A vulnerability has been identified in RUGGEDCOM RST2428P (6…5.3
- CVE-2024-41798A vulnerability has been identified in SENTRON 7KM PAC3200 (…9.8
- CVE-2024-4180The Events Calendar WordPress plugin before 6.4.0.1 does not…9.1
- CVE-2024-41800Craft is a content management system (CMS). Craft CMS 5 allo…7.5
- CVE-2024-41801OpenProject is open source project management software. Prio…6.1
- CVE-2024-41802Xibo is a content management system (CMS). An SQL injection …8.1
- CVE-2024-41803Xibo is a content management system (CMS). An SQL injection …4.9
- CVE-2024-41804Xibo is a content management system (CMS). An SQL injection …6.5
Are you affected by CVE-2024-41799?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
