Delphix Privilege Escalation Vulnerability via OS Login on Google Cloud Platform
Vulnerability
A privilege escalation vulnerability has been identified in Delphix Continuous Data and Continuous Compliance versions 14.0.0.0 prior to 2025.2.0.0. An attacker who can create user accounts during virtual machine deployment on Google Cloud Platform (GCP) using the OS Login feature can log in via SSH. This access provides command-line control over the operating system, allowing the attacker to access sensitive data on the VM, install malicious software, and disrupt or disable the VM's functionality.
Impact
Exploitation of this vulnerability allows for unauthorized SSH access to the VM, with command-line control over the operating system. This access can be used to steal sensitive data, install malicious software, and disrupt or disable VM operations.
Remediation
Users can upgrade to Delphix version 2025.2.0.1 to address this vulnerability.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
