JumpCloud Remote Assist Windows Agent Vulnerability Allows Privilege Escalation
A critical local privilege escalation vulnerability has been identified in the JumpCloud Remote Assist for Windows agent. This vulnerability allows any low-privileged user on a Windows system to gain NT AUTHORITY\SYSTEM privileges or potentially crash…
A critical local privilege escalation vulnerability has been identified in the JumpCloud Remote Assist for Windows agent. This vulnerability allows any low-privileged user on a Windows system to gain NT AUTHORITY\SYSTEM privileges or potentially crash the machine.
The vulnerability, tracked as CVE-2025-34352, affects JumpCloud Remote Assist for Windows versions prior to 0.317.0 and is rated High severity with a CVSS v4.0 score of 8.5.
Property Details
Vulnerability ID CVE-2025-34352
Severity High (CVSS v4.0 Score: 8.5)
Affected Component JumpCloud Remote Assist for Windows
A critical local privilege escalation vulnerability has been identified in the JumpCloud Remote Assist for Windows agent.
Affected Versions All versions prior to 0.317.0
Attack Vector Local (LPE)
The JumpCloud Agent operates with high system privileges to manage endpoints and enforce policies. As such, any vulnerability within its components could lead to full device compromise. The vulnerability is found in the Windows uninstaller of the JumpCloud Remote Assist component, affecting the uninstallation process, which runs under NT AUTHORITY\SYSTEM privileges.
The uninstaller executes file operations in the user's %TEMP% directory, a location accessible by low-privileged users. An attacker can manipulate a file named Un_A.exe within this directory, potentially allowing:
Arbitrary file write: This could lead to a Denial of Service (DoS) by causing a Blue Screen of Death (BSOD). Arbitrary file deletion: This may result in acquiring a full SYSTEM shell, providing persistent control over the endpoint.
The exploitation enables full control over the machine, allowing actions such as malware installation, data theft, or lateral movement within the network.
JumpCloud has released an update to address this vulnerability. It is advised that all organizations using JumpCloud Remote Assist for Windows update to version 0.317.0 or later. Security teams should ensure all managed Windows devices have received the update and review endpoint hardening policies to prevent similar vulnerabilities.
Prompt patching is crucial, as the vulnerability is easily exploitable locally and compromises the integrity of endpoint management and remote assistance tools.
Based on reporting by GBHackers.
