Skip to finding
important · Privilege — Windows

Rapid7 assessment content could turn a writable Windows PATH entry into SYSTEM execution.

Affects

Rapid7 Insight Agent on Windows, an endpoint agent that runs centrally delivered InsightVM assessment content.

The attacker first needs a non-administrator-writable machine PATH directory ahead of Visual Studio Code. A planted executable named code is then selected by a SYSTEM assessment check.

Detail and 2 sources
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Friday, September 25, 2026