CVE-2024-0259
HIGHFortra Robot Schedule Enterprise Agent for Windows < 3.04 - Privilege Escalation via Service Executable Overwrite
Title source: llmDescription
Fortra's Robot Schedule Enterprise Agent for Windows prior to version 3.04 is susceptible to privilege escalation. A low-privileged user can overwrite the service executable. When the service is restarted, the replaced binary runs with local system privileges, allowing a low-privileged user to gain elevated privileges.
References (2)
Core 2
Core References
Release Notes
https://hstechdocs.helpsystems.com/releasenotes/Content/_ProductPages/Robot/RobotScheduleEnterprise.htm
Vendor Advisory
https://www.fortra.com/security/advisory/fi-2024-005
Scores
CVSS v3
7.3
EPSS
0.0028
EPSS Percentile
19.9%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-276
Status
published
Products (1)
fortra/robot_schedule
< 3.04
Published
Mar 28, 2024
Tracked Since
Feb 18, 2026