CVE-2024-0259

Fortra's Robot Schedule Enterprise Agent for Windows prior to version 3.04 is susceptible to privilege escalation. A low-privileged user can overwrite the service executable. When the service is restarted, the replaced binary runs with local system privileges, allowing a low-privileged user to gain elevated privileges.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:fortra:robot_schedule:*:*:*:*:enterprise:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

09 Apr 2025, 15:42

Type Values Removed Values Added
First Time Microsoft
Fortra robot Schedule
Fortra
Microsoft windows
CPE cpe:2.3:a:fortra:robot_schedule:*:*:*:*:enterprise:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
References () https://hstechdocs.helpsystems.com/releasenotes/Content/_ProductPages/Robot/RobotScheduleEnterprise.htm - () https://hstechdocs.helpsystems.com/releasenotes/Content/_ProductPages/Robot/RobotScheduleEnterprise.htm - Release Notes
References () https://www.fortra.com/security/advisory/fi-2024-005 - () https://www.fortra.com/security/advisory/fi-2024-005 - Vendor Advisory

21 Nov 2024, 08:46

Type Values Removed Values Added
Summary
  • (es) El Robot Schedule Enterprise Agent de Fortra para Windows anterior a la versión 3.04 es susceptible a una escalada de privilegios. Un usuario con pocos privilegios puede sobrescribir el ejecutable del servicio. Cuando se reinicia el servicio, el binario reemplazado se ejecuta con privilegios del sistema local, lo que permite que un usuario con pocos privilegios obtenga permisos elevados.
References () https://hstechdocs.helpsystems.com/releasenotes/Content/_ProductPages/Robot/RobotScheduleEnterprise.htm - () https://hstechdocs.helpsystems.com/releasenotes/Content/_ProductPages/Robot/RobotScheduleEnterprise.htm -
References () https://www.fortra.com/security/advisory/fi-2024-005 - () https://www.fortra.com/security/advisory/fi-2024-005 -

28 Mar 2024, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-03-28 15:15

Updated : 2025-04-09 15:42


NVD link : CVE-2024-0259

Mitre link : CVE-2024-0259

CVE.ORG link : CVE-2024-0259


JSON object : View

Products Affected

microsoft

  • windows

fortra

  • robot_schedule
CWE
CWE-276

Incorrect Default Permissions