Privilege Escalation Vulnerability in IBM Robotic Process Automation
CVE-2024-51448
6.7MEDIUM
What is CVE-2024-51448?
A privilege escalation vulnerability exists in IBM Robotic Process Automation versions 21.0.0 through 21.0.7.17 and 23.0.0 through 23.0.18, which may allow a local user to elevate their privileges. This issue arises due to inappropriate file permission settings, permitting non-privileged users to replace executable files associated with the nssm.exe service. Once substituted, any subsequent restarts of the service or server will execute the unauthorized binary with elevated administrator rights, potentially compromising system security.
Affected Version(s)
Robotic Process Automation 21.0.0 <= 21.0.7.17
Robotic Process Automation 23.0.0 <= 23.0.18