#VU101202 Insecure Inherited Permissions in IBM Robotic Process Automation - CVE-2024-51448
Published: December 4, 2024
IBM Robotic Process Automation
IBM Corporation
Description
The vulnerability allows a local privileged user to escalate privileges on the system.
The vulnerability exists due to all files in the install inherit the file permissions of the parent directory. A local privileged user can substitute any executable for the nssm.exe service. A subsequent service or server restart will then run that binary with administrator privilege.