Vulnerability Details CVE-2024-51448
IBM Robotic Process Automation 21.0.0 through 21.0.7.17 and 23.0.0 through 23.0.18 could allow a local user to escalate their privileges. All files in the install inherit the file permissions of the parent directory and therefore a non-privileged user can substitute any executable for the nssm.exe service. A subsequent service or server restart will then run that binary with administrator privilege.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 1.0%
CVSS Severity
CVSS v3 Score 6.7
Products affected by CVE-2024-51448
-
cpe:2.3:a:ibm:robotic_process_automation:21.0.0
-
cpe:2.3:a:ibm:robotic_process_automation:21.0.1
-
cpe:2.3:a:ibm:robotic_process_automation:21.0.1.2
-
cpe:2.3:a:ibm:robotic_process_automation:21.0.1.5
-
cpe:2.3:a:ibm:robotic_process_automation:21.0.2
-
cpe:2.3:a:ibm:robotic_process_automation:21.0.2.1
-
cpe:2.3:a:ibm:robotic_process_automation:21.0.2.2
-
cpe:2.3:a:ibm:robotic_process_automation:21.0.2.5
-
cpe:2.3:a:ibm:robotic_process_automation:21.0.3
-
cpe:2.3:a:ibm:robotic_process_automation:21.0.4
-
cpe:2.3:a:ibm:robotic_process_automation:21.0.5
-
cpe:2.3:a:ibm:robotic_process_automation:21.0.6
-
cpe:2.3:a:ibm:robotic_process_automation:21.0.7
-
cpe:2.3:a:ibm:robotic_process_automation:21.0.7.1
-
cpe:2.3:a:ibm:robotic_process_automation:21.0.7.17
-
cpe:2.3:a:ibm:robotic_process_automation:21.0.7.3
-
cpe:2.3:a:ibm:robotic_process_automation:21.0.7.6
-
cpe:2.3:a:ibm:robotic_process_automation:23.0.0
-
cpe:2.3:a:ibm:robotic_process_automation:23.0.1
-
cpe:2.3:a:ibm:robotic_process_automation:23.0.18
-
cpe:2.3:a:ibm:robotic_process_automation:23.0.2
-
cpe:2.3:a:ibm:robotic_process_automation:23.0.3
-
cpe:2.3:a:ibm:robotic_process_automation:23.0.9