Privilege Escalation Vulnerability in IBM Robotic Process Automation
CVE-2024-51448

6.7MEDIUM

Key Information:

Vendor
IBM
Vendor
CVE Published:
18 January 2025

Summary

A privilege escalation vulnerability exists in IBM Robotic Process Automation versions 21.0.0 through 21.0.7.17 and 23.0.0 through 23.0.18, which may allow a local user to elevate their privileges. This issue arises due to inappropriate file permission settings, permitting non-privileged users to replace executable files associated with the nssm.exe service. Once substituted, any subsequent restarts of the service or server will execute the unauthorized binary with elevated administrator rights, potentially compromising system security.

Affected Version(s)

Robotic Process Automation 21.0.0 <= 21.0.7.17

Robotic Process Automation 23.0.0 <= 23.0.18

References

CVSS V3.1

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.