Horizon Alert
Summary of the vulnerability and why it matters
A vulnerability in Velociraptor, an endpoint visibility tool, allows users with investigative privileges to execute arbitrary commands as an administrator by bypassing security checks. This could enable unauthorized access and control over the Velociraptor server.
- Allows basic users to run admin commands.
- Critical for protecting server and data integrity.
- Confirm relevance and assess exposure immediately.
Attack Path
How an attacker could exploit the issue
An attacker with investigator privileges can target the hunt object within Velociraptor. By manipulating an internal field meant to store pre-compiled VQL, the attacker can bypass normal access controls and inject arbitrary VQL statements. This allows them to execute commands with administrator-level permissions on the Velociraptor server.
- Investigator role required to schedule hunts.
- Setting internal `compiled_collector_args` field.
- Arbitrary code execution as administrator.
Live Threat
Current exploitation, exposure, and threat context
An investigator user could manipulate compiled VQL statements to execute arbitrary VQL as an administrator on the Velociraptor server when supported by the advisory.
- Administrator credentials and server control.
- API calls to schedule hunts.
- Arbitrary VQL execution.
Operational Fix
Recommended remediation, mitigation, and detection steps
The Velociraptor server owner, likely a security operations or platform team, must identify all deployed Velociraptor instances. Once identified, determine reachability and business criticality to prioritize remediation, involving vendor coordination if necessary.
- Identify all Velociraptor instances.
- Confirm reachability and business criticality.
- Plan remediation based on risk.