In WhatsUp Gold versions released before 2024.0.1, a remote unauthenticated attacker could leverage NmAPI.exe to create or change an existing registry value in registry path HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Ipswitch\.
CVE ID: CVE-2024-8785
CVSS Base Severity: CRITICAL
CVSS Base Score: 9.8
Vendor: Progress Software Corporation
Product: WhatsUp Gold
EPSS Score: 0.05% (probability of being exploited)
EPSS Percentile: 23.36% (scored less or equal to compared to others)
EPSS Date: 2025-02-03 (when was this score calculated)