Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
JumpCloud Remote Assist for Windows Agent Flaw Let Attackers Escalate Privilege

JumpCloud Remote Assist for Windows Agent Flaw Let Attackers Escalate Privilege

Posted on December 15, 2025December 15, 2025 By CWS

The JumpCloud Distant Help vulnerability (CVE-2025-34352) exposes Home windows methods to native privilege escalation and denial-of-service assaults. Found by XM Cyber researcher Hillel Pinto, the flaw stems from insecure file operations within the agent’s uninstaller.​

The JumpCloud Distant Help for Home windows agent, variations previous to 0.317.0, runs as NT AUTHORITYSYSTEM and performs file create, write, delete, and execute actions within the user-controlled %TEMP% listing with out correct validation.

This permits low-privileged native attackers to leverage symbolic hyperlinks or mount factors for arbitrary file manipulation. JumpCloud, a cloud listing service utilized by over 180,000 organizations, deploys this agent on managed endpoints to implement insurance policies and help distant entry.​

XM Cyber evaluation reveals the primary JumpCloud agent triggers Distant Help uninstallation throughout its personal elimination course of. The uninstaller checks for recordsdata like Un_A.exe in %TEMP%~nsuA.tmp, deleting present ones earlier than writing and executing new content material.

Attackers can pre-create this listing with weak permissions, redirecting operations by way of hyperlink following (CWE-59) or short-term file points (CWE-378). Reverse engineering, aided by Go binary metadata restoration, traces the trail development from surroundings variables to execution.​

For DoS, attackers create a mount level from %TEMP%~nsuA.tmp to a system listing like RPCControl, then symlink Un_A.exe to overwrite drivers similar to cng.sys, triggering crashes.

Privilege escalation makes use of a TOCTOU race with oplocks on C:Config.Msi, redirecting deletes to allow SYSTEM shell by way of Home windows Installer tips. These primitives grant persistent endpoint management, amplifying dangers in enterprise environments.​

Organizations should improve to JumpCloud Distant Help 0.317.0 or later instantly. Safety groups ought to audit brokers for operations in user-writable paths, implement ACLs on temp directories, and monitor for uninstall triggers. JumpCloud confirmed the problem post-disclosure and launched the repair promptly.​

Observe us on Google Information, LinkedIn, and X for each day cybersecurity updates. Contact us to function your tales.

Cyber Security News Tags:Agent, Assist, Attackers, Escalate, Flaw, JumpCloud, Privilege, Remote, Windows

Post navigation

Previous Post: Threat Actors Advertising ‘MioLab MacOS’ Infostealer on an Underground Forum
Next Post: Jaguar Land Rover Confirms Employee Data Stolen in August Cyberattack

Related Posts

Closing the Costly SOC Triage-to-Response Gap Closing the Costly SOC Triage-to-Response Gap Cyber Security News
Critical LiteSpeed cPanel Plugin Flaw Exploited for Root Access Critical LiteSpeed cPanel Plugin Flaw Exploited for Root Access Cyber Security News
Critical LiteLLM Vulnerability Risks Cloud Security Critical LiteLLM Vulnerability Risks Cloud Security Cyber Security News
Laravel APP_KEY Vulnerability Allows Remote Code Execution Laravel APP_KEY Vulnerability Allows Remote Code Execution Cyber Security News
PipeMagic Malware Mimic as ChatGPT App Exploits Windows Vulnerability to Deploy Ransomware PipeMagic Malware Mimic as ChatGPT App Exploits Windows Vulnerability to Deploy Ransomware Cyber Security News
Hackers Actively Exploiting WordPress Plugin Vulnerability to Gain Admin Access Hackers Actively Exploiting WordPress Plugin Vulnerability to Gain Admin Access Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • F-Droid 2.0 Debuts with Major Redesign for App Discovery
  • China and US to Create AI Safety Channel Amid Ongoing Talks
  • Lunex Stealer Exploits AMD Driver for Credential Theft
  • Local AI Model Evades EDR Detection with Modified Credential Dumper
  • Enhancing AI Agent Security with Zero Trust Principles

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • F-Droid 2.0 Debuts with Major Redesign for App Discovery
  • China and US to Create AI Safety Channel Amid Ongoing Talks
  • Lunex Stealer Exploits AMD Driver for Credential Theft
  • Local AI Model Evades EDR Detection with Modified Credential Dumper
  • Enhancing AI Agent Security with Zero Trust Principles

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark