There exists an insecure default user permission in Google Cloud Migrate to containers from version 1.1.0 to 1.2.2 Windows installs. A local "m2cuser" was greated with administrator privileges. This posed a security risk if the "analyze" or "generate" commands were interrupted or skipping the action to delete the local user “m2cuser”. We recommend upgrading to 1.2.3 or beyond
History

Wed, 30 Jul 2025 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google migrate To Containers
CPEs cpe:2.3:a:google:migrate_to_containers:*:*:*:*:*:*:*:*
Vendors & Products Google
Google migrate To Containers

Sat, 12 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00029}

epss

{'score': 0.0003}


Wed, 16 Oct 2024 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Google Cloud
Google Cloud migrate To Containers
CPEs cpe:2.3:a:google_cloud:migrate_to_containers:*:*:*:*:*:*:*:*
Vendors & Products Google Cloud
Google Cloud migrate To Containers
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Oct 2024 09:00:00 +0000

Type Values Removed Values Added
Description There exists an insecure default user permission in Google Cloud Migrate to containers from version 1.1.0 to 1.2.2 Windows installs. A local "m2cuser" was greated with administrator privileges. This posed a security risk if the "analyze" or "generate" commands were interrupted or skipping the action to delete the local user “m2cuser”. We recommend upgrading to 1.2.3 or beyond
Title Insecure user permissions in Google Cloud Migrate to Containers for Windows
Weaknesses CWE-276
References
Metrics cvssV4_0

{'score': 5.9, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:P/VC:H/VI:L/VA:L/SC:H/SI:L/SA:L/S:P/AU:Y/R:A/V:D/RE:L/U:Green'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Google

Published: 2024-10-16T08:43:51.015Z

Updated: 2024-10-16T16:24:16.999Z

Reserved: 2024-10-11T11:17:41.006Z

Link: CVE-2024-9858

cve-icon Vulnrichment

Updated: 2024-10-16T16:24:04.455Z

cve-icon NVD

Status : Analyzed

Published: 2024-10-16T09:15:03.550

Modified: 2025-07-30T19:32:10.007

Link: CVE-2024-9858

cve-icon Redhat

No data.