CVE-2024-9858: exploitation status and patch state

CVE-2024-9858 · CVSS 7.8 HIGH · EPSS <1%

There exists an insecure default user permission in Google Cloud Migrate to containers from version 1.1.0 to 1.2.2 Windows installs. A local "m2cuser" was greated with administrator privileges. This posed a security risk if the "analyze" or "generate" commands were interrupted or skipping the action to delete the local user “m2cuser”. We recommend upgrading to 1.2.3 or beyond

Is CVE-2024-9858 exploited?

Which products and versions are affected?

No affected package list recorded here yet.

Is there a patch?

No patch identifier recorded here yet.

What PlainSec published about CVE-2024-9858

Primary sources

What this record does not say

KEV and EPSS are re-checked daily. Record last updated 2026-08-15.