Privilege Escalation in Robot Schedule Enterprise Agent for Windows prior to version 3.04
Vulnerability Description
Fortra's Robot Schedule Enterprise Agent for Windows prior to version 3.04 is susceptible to privilege escalation. A low-privileged user can overwrite the service executable. When the service is restarted, the replaced binary runs with local system privileges, allowing a low-privileged user to gain elevated privileges.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-0259
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Travis Dotseth, Prime Therapeutics
References
More from Fortra
View All →Affected Vendor
Fortra
View all reports →