BlackTree Security · Infrastructure · Automation · AI

The Security Agent That Could Turn a Writable PATH Into SYSTEM

Rapid7 has disclosed a local privilege-escalation flaw in Windows assessment content. A check invoked code without a full path while running as SYSTEM. A low-privilege user could plant that executable in a writable machine PATH directory searched before the legitimate Visual Studio Code location.

The record assigns CVE-2026-89325 a CVSS score of 7.8. It identifies assessment content at or below 0.0.261.0 as affected, regardless of installed agent version. Rapid7’s release documentation records the fix in content 0.0.269.0, available from 15 September. Rapid7 says delivery was automatic and requires no customer action.

Automatic remediation does not describe historical exposure

The reviewed vendor material does not report malicious exploitation. This is not a remote entry point: it requires a local foothold and the relevant writable PATH ordering. The useful operational question is whether those conditions previously coincided on a host, rather than whether every endpoint now needs a manually installed agent update.

Treat content delivery and executable version as separate inventory facts. Ask whether an endpoint was connected, receiving assessment content and reporting health during the rollout. A console that only records the agent version may not answer that question.

Review the environment used by privileged software

A privileged process can inherit assumptions from its environment that a normal user is able to influence. A PATH audit therefore has value beyond this single check. Document who can write each machine-level search directory and test any proposed removal against legitimate software dependencies before rollout.

What defenders should verify

  • Confirm content health. Verify that agents have received assessment content 0.0.269.0 or later and are not isolated, stale or failing to report.
  • Audit the machine PATH. Identify directories writable by ordinary users, especially entries ordered before trusted system and application directories.
  • Hunt for planted executables. Search writable PATH locations for files named code and review creation time, signer, hash, owner and execution history.
  • Review SYSTEM process launches. Look for the Rapid7 Agent or its child processes starting an unexpected code binary from a non-standard directory.
  • Fix the underlying configuration. Removing user-writable machine PATH entries reduces exposure to this class of issue beyond one assessment check.
  • Preserve uncertainty. The reviewed vendor material does not report malicious exploitation or a public proof of concept. A risky PATH is exposure, not proof of compromise.

BlackTree recently covered a Veeam Agent path to SYSTEM with public proof-of-concept code. The products, mechanisms and exploitation status differ, but both show why management and recovery agents deserve the same attack-path scrutiny as the software they monitor.

Sources

Leave a Reply

Your email address will not be published. Required fields are marked *