Rapid7 Insight Agent Local Privilege Escalation Vulnerability on Windows

Vulnerability

A local privilege escalation vulnerability has been identified in the Rapid7 Insight Agent, specifically in versions greater than 4.1.0.2. This vulnerability allows users to gain SYSTEM-level control on a Windows host. The issue arises because the agent service, upon startup, tries to load an OpenSSL configuration file from a non-existent directory that standard users can write to. By placing a crafted openssl.cnf file in this location, an attacker can manipulate the high-privilege service into executing arbitrary commands. This exploitation enables an unprivileged user to bypass security measures and achieve full control of the host with the agent's SYSTEM-level access.

Impact

Exploitation of this vulnerability allows for local privilege escalation, enabling an unprivileged user to gain SYSTEM-level access on the affected Windows host, potentially leading to a full compromise of the system.

Remediation

Users can update to Rapid7 Insight Agent version 4.1.0.2 or later, which addresses this vulnerability by removing the agent's attempt to load an OpenSSL configuration file from the exploitable directory. Instructions for updating the Rapid7 Insight Agent can be found in the Rapid7 documentation.

Added: Apr 17, 2026, 6:21 AM
Updated: Apr 17, 2026, 6:21 AM

Vulnerability Rating

Custom Algorithm
spread
6.6
impact
10.0
exploitability
4.2
remediation
0.0
relevance
6.1
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.