>> All posts

CVE-2024-4885: Progress WhatsUp Gold path traversal to unauthenticated RCE

The short version: Progress WhatsUp Gold — network and infrastructure monitoring — has a path-traversal flaw (CVE-2024-4885) that lets an unauthenticated attacker execute commands on the server with the monitoring service's privileges. It's in CISA's KEV catalog, a public exploit exists, and a fix is out. If you run WhatsUp Gold, patch and verify. Steady hands — but move.

At a glance

FactDetail
Our severity takeCritical — in practice and on paper
CVSS v3.1 (NVD)9.8 — Critical · AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS~99.3% · 99.9th percentile (2026-07-17)
In CISA KEV?Yes — remediation was due 2025-03-24
Known exploited?Yes — KEV-listed; public exploitation
Vulnerability typeCWE-22 path traversal → unauthenticated remote code execution
Requires authenticated session?No — pre-authentication
AffectedWhatsUp Gold released before 2023.1.3
Fixed in2023.1.3 (and later)

What you need to know

CVE-2024-4885 is a path traversal in Progress WhatsUp Gold. A specific export function (WhatsUp.ExportUtilities.Export.GetFileWithoutZip) mishandles attacker-controlled paths, letting an unauthenticated attacker execute commands with the privileges of the monitoring service account (iisapppool\nmconsole).

Why this belongs at the top of the queue:

  • It's the monitoring platform. WhatsUp Gold reaches broadly across an environment to poll devices — code execution there is a strong pivot point.
  • It's pre-authentication and network-reachable. No credential, no chain — just a crafted request.
  • It's exploited. KEV-listed with a public exploit and a very high EPSS, so an exposed, unpatched instance is a live target.

How serious we see it

Critical — the 9.8 is earned here.

Unauthenticated remote code execution on an internet-facing monitoring server, KEV-listed with public exploitation, is exactly what belongs at the top of the queue. We rate it by what it does and how it's used. The bounded, reassuring part is that it's specific and fixed: WhatsUp Gold before 2023.1.3, with a published patch and quick-to-confirm exposure.

Recommendations

Straight from Progress's advisory and CISA:

  1. Patch now. Upgrade WhatsUp Gold to 2023.1.3 or later.
  2. Restrict exposure. Keep WhatsUp Gold off the open internet; limit it to trusted networks or a VPN.
  3. Hunt for prior use. Review for indicators of compromise and command execution given active exploitation.
  4. If compromised, respond. Rebuild where warranted and rotate credentials and secrets the server could reach.
  5. Confirm your exposure first. Verify whether you run WhatsUp Gold and which build.

How BreachRisk sees it

BreachRisk discovers internet-facing WhatsUp Gold portals from the outside, fingerprints the product and version, and flags exposure tied to this KEV-listed, actively exploited CVE so it rises to the top of your results. Safe verification isn't offered for this one — a reliable confirmation would require a blind, out-of-band exploitation attempt — so BreachRisk detects and prioritizes the exposure rather than exploiting it. The value is that an exposed, affected instance is already on your map when the flaw matters.

References

See your cyber risk, proven.