CVE-2018-17305

HIGH

UiPath Orchestrator <2018.2.4 - Privilege Escalation, RCE

Title source: llm
STIX 2.1

Description

UiPath Orchestrator through 2018.2.4 allows any authenticated user to change the information of arbitrary users (even administrators) leading to privilege escalation and remote code execution.

References (1)

Core 1
Core References
Patch, Release Notes, Vendor Advisory x_refsource_confirm
https://www.uipath.com/product/release-notes/uipath-v2018.1.7

Scores

CVSS v3 8.8
EPSS 0.0181
EPSS Percentile 82.9%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-732
Status published
Products (1)
uipath/orchestrator < 2018.2.4
Published Apr 11, 2019
Tracked Since Feb 18, 2026