Privilege Escalation Vulnerability in IBM Robotic Process Automation
CVE-2024-51448
6.7MEDIUM
Summary
A privilege escalation vulnerability exists in IBM Robotic Process Automation versions 21.0.0 through 21.0.7.17 and 23.0.0 through 23.0.18, which may allow a local user to elevate their privileges. This issue arises due to inappropriate file permission settings, permitting non-privileged users to replace executable files associated with the nssm.exe service. Once substituted, any subsequent restarts of the service or server will execute the unauthorized binary with elevated administrator rights, potentially compromising system security.
Affected Version(s)
Robotic Process Automation 21.0.0 <= 21.0.7.17
Robotic Process Automation 23.0.0 <= 23.0.18
References
CVSS V3.1
Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved