Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-51448


IBM Robotic Process Automation 21.0.0 through 21.0.7.17 and 23.0.0 through 23.0.18 could allow a local user to escalate their privileges. All files in the install inherit the file permissions of the parent directory and therefore a non-privileged user can substitute any executable for the nssm.exe service. A subsequent service or server restart will then run that binary with administrator privilege.


Published

2025-01-18T15:15:08.183

Last Modified

2025-03-25T14:06:48.877

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 6.7 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-277
  • Type: Primary
    CWE-732

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application ibm robotic_process_automation ≤ 21.0.7.17 Yes
Application ibm robotic_process_automation ≤ 23.0.18 Yes

References