6.7
CVE-2024-51448
- EPSS 0.03%
- Veröffentlicht 18.01.2025 15:15:08
- Zuletzt bearbeitet 25.03.2025 14:06:48
- Quelle psirt@us.ibm.com
- CVE-Watchlists
- Unerledigt
IBM Robotic Process Automation privilege escalation
IBM Robotic Process Automation 21.0.0 through 21.0.7.17 and 23.0.0 through 23.0.18 could allow a local user to escalate their privileges. All files in the install inherit the file permissions of the parent directory and therefore a non-privileged user can substitute any executable for the nssm.exe service. A subsequent service or server restart will then run that binary with administrator privilege.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Robotic Process Automation Version >= 21.0.0 <= 21.0.7.17
Ibm ≫ Robotic Process Automation Version >= 23.0.0 <= 23.0.18
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.03% | 0.071 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| psirt@us.ibm.com | 6.7 | 0.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
|
CWE-277 Insecure Inherited Permissions
A product defines a set of insecure permissions that are inherited by objects that are created by the program.
CWE-732 Incorrect Permission Assignment for Critical Resource
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.