CVE-2025-34352Disclosure

LOWCVSS 8.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

JumpCloud Remote Assist for Windows versions prior to 0.317.0 include an uninstaller that is invoked by the JumpCloud Windows Agent as NT AUTHORITY\SYSTEM during agent uninstall or update operations. The Remote Assist uninstaller performs privileged create, write, execute, and delete actions on predictable files inside a user-writable %TEMP% subdirectory without validating that the directory is trusted or resetting its ACLs when it already exists. A local, low-privileged attacker can pre-create the directory with weak permissions and leverage mount-point or symbolic-link redirection to (a) coerce arbitrary file writes to protected locations, leading to denial of service (e.g., by overwriting sensitive system files), or (b) win a race to redirect DeleteFileW() to attacker-chosen targets, enabling arbitrary file or folder deletion and local privilege escalation to SYSTEM. This issue is fixed in JumpCloud Remote Assist 0.317.0 and affects Windows systems where Remote Assist is installed and managed through the Agent lifecycle.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-59CWE-378

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 1 mentions (2026-03-19); latest day: 1
  • 3 total mentions across 3 days

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-03-19: 1Mentions · 2026-03-28: 1Mentions · 2026-04-16: 1Patch / Workaround · 2026-03-28: 1Technical Details · 2026-03-19: 1Technical Details · 2026-03-28: 1Technical Details · 2026-04-16: 103-1903-2804-16
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Full discourse3 posts
  • reverseame@reverseame
    Disclosure

    JUMPSHOT: XM Cyber Uncovers Critical Local Privilege Escalation (CVE-2025-34352) in JumpCloud Agent https://xmcyber.com/blog/jumpshot-xm-cyber-uncovers-critical-local-privilege-escalation-cve-2025-34352-in-jumpcloud-agent/

    Post summary

    XM Cyber has disclosed a critical local privilege escalation vulnerability (CVE‑2025‑34352) in JumpCloud Agent; the post does not contain PoC code, exploit details, or patch information.

    01010842
    22.0K followersView on X
  • InfoSecSherpa 🏔️@InfoSecSherpa
    Disclosure

    "The flaw allows any low-privileged local user to exploit insecure file operations—arbitrary file write/delete—performed by the agent running as NT AUTHORITY\SYSTEM within the user’s temporary directory." https://cybersec.xmcyber.com/s/umpshot-xm-cyber-uncovers-critical-local-privilege-escalation-cve-2025-34352-in-jumpcloud-agent-25993 https://t.co/KPh6AkLJ9g

    Post summary

    The post announces a newly disclosed local privilege escalation vulnerability (CVE‑2025‑34352) in the JumpCloud agent that permits low‑privileged local users to perform arbitrary file write/delete with SYSTEM credentials.

    01010260
    51.6K followersView on X
  • John Christly@christly
    Disclosure

    https://cybersec.xmcyber.com/s/umpshot-xm-cyber-uncovers-critical-local-privilege-escalation-cve-2025-34352-in-jumpcloud-agent-26204/1

    Post summary

    The post reports the discovery of a critical local privilege escalation vulnerability (CVE‑2025‑34352) in JumpCloud agent 26204, includes technical details, and indicates a patch is available.

    0000085
    438 followersView on X

Explore more