CVE-2024-0259

Fortra's Robot Schedule Enterprise Agent for Windows prior to version 3.04 is susceptible to privilege escalation. A low-privileged user can overwrite the service executable. When the service is restarted, the replaced binary runs with local system privileges, allowing a low-privileged user to gain elevated privileges.
Configurations

No configuration.

History

21 Nov 2024, 08:46

Type Values Removed Values Added
Summary
  • (es) El Robot Schedule Enterprise Agent de Fortra para Windows anterior a la versión 3.04 es susceptible a una escalada de privilegios. Un usuario con pocos privilegios puede sobrescribir el ejecutable del servicio. Cuando se reinicia el servicio, el binario reemplazado se ejecuta con privilegios del sistema local, lo que permite que un usuario con pocos privilegios obtenga permisos elevados.
References () https://hstechdocs.helpsystems.com/releasenotes/Content/_ProductPages/Robot/RobotScheduleEnterprise.htm - () https://hstechdocs.helpsystems.com/releasenotes/Content/_ProductPages/Robot/RobotScheduleEnterprise.htm -
References () https://www.fortra.com/security/advisory/fi-2024-005 - () https://www.fortra.com/security/advisory/fi-2024-005 -

28 Mar 2024, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-03-28 15:15

Updated : 2024-11-21 08:46


NVD link : CVE-2024-0259

Mitre link : CVE-2024-0259

CVE.ORG link : CVE-2024-0259


JSON object : View

Products Affected

No product.

CWE
CWE-276

Incorrect Default Permissions