CVE-2024-8785: Progress WhatsUp Gold

Medium severity, CVSS 5.3. EPSS: 9.5% chance of exploitation in the next 30 days.

In WhatsUp Gold versions released before 2024.0.1, a remote unauthenticated attacker could leverage NmAPI.exe to create or change an existing registry value in registry path HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Ipswitch\.

Affected products

  • Progress WhatsUp Gold: before 24.0.1 (fixed in 24.0.1)

Published 2024-12-02. Last modified 2026-06-17.