LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2024-4885: Progress WhatsUp Gold Path Traversal Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 3, 2025
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Mar 24, 2025
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2024-4885 to its Known Exploited Vulnerabilities catalog on Mar 3, 2025, with a federal patch deadline of Mar 24, 2025 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Progress WhatsUp Gold contains a path traversal vulnerability that allows an unauthenticated attacker to achieve remote code execution.

CVE-2024-4885 is a path traversal vulnerability in Progress WhatsUp Gold that allows an unauthenticated attacker to achieve remote code execution. Network monitoring platforms like this often sit in privileged positions with broad visibility into infrastructure, so successful abuse can give an attacker a foothold for further movement or control. Specifics such as exact affected releases must be confirmed against the vendor advisory.

CISA notes the issue permits remote code execution without authentication and directs organizations to apply vendor mitigations, follow applicable BOD 22-01 guidance for cloud services, or discontinue use if mitigations are unavailable. Known ransomware use is not documented.

How it works

The weakness is classified as CWE-22 (path traversal). In this class of flaw, software fails to properly neutralize special elements such as directory traversal sequences in user-supplied input that is used to construct a filesystem path. An attacker who can reach the vulnerable interface can craft requests that escape the intended directory and access or write files outside the allowed location.

According to the CISA summary, Progress WhatsUp Gold contains a path traversal vulnerability that allows an unauthenticated attacker to achieve remote code execution. Public detail on the precise request format or target endpoints is limited; defenders should treat any unauthenticated path-handling functionality in the product as potentially abusable and confirm the exact attack surface against the vendor advisory. No exploit code or step-by-step mechanics are provided here.

Am I affected? How to find it in your systems

Progress WhatsUp Gold is typically deployed as an on-premises or hybrid network monitoring and management solution, often running on Windows servers with web interfaces for configuration and reporting. Inventory efforts should focus on systems performing network discovery, performance monitoring, or alerting.

Telemetry from EDR, network IDS, or WAF can surface anomalous requests to the monitoring host; correlate these with authentication failures or sudden privilege changes.

How to remediate

Patch first. Apply the vendor update named in the Progress advisory for CVE-2024-4885. After installation, verify the new version is running and that the previously vulnerable endpoints no longer accept the traversal patterns described by the vendor.

Re-scan or re-inventory after patching to confirm the vulnerable component is no longer present.

If you can't patch immediately

Until the vendor update can be applied, reduce exposure with compensating controls:

If your data may have been exposed

Actively exploited vulnerabilities of this class can lead to full system compromise and subsequent data exposure. Review logs for signs of successful exploitation, rotate any credentials that may have been accessible from the affected host, and examine connected systems for lateral movement. Readers can run a free exposure scan of their email addresses to check whether those addresses appear in known breach data sets.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedProgress · WhatsUp Gold
WeaknessCWE-22
Added to CISA KEVMar 3, 2025
Federal patch deadlineMar 24, 2025
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities