CVE-2024-39934

HIGH

Robotmk <2.0.1 - Privilege Escalation

Title source: llm
STIX 2.1

Description

Robotmk before 2.0.1 allows a local user to escalate privileges (e.g., to SYSTEM) if automated Python environment setup is enabled, because the "shared holotree usage" feature allows any user to edit any Python environment.

Scores

CVSS v3 7.8
EPSS 0.0018
EPSS Percentile 7.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-284
Status published
Published Jul 04, 2024
Tracked Since Feb 18, 2026