Loading HuntDB...

GHSA-6pxp-6h5g-5389

GitHub Security Advisory

⚠ Unreviewed MODERATE Has CVE

Advisory Details

IBM Robotic Process Automation 21.0.0 through 21.0.7.17 and 23.0.0 through 23.0.18 could allow a local user to escalate their privileges. All files in the install inherit the file permissions of the parent directory and therefore a non-privileged user can substitute any executable for the nssm.exe service. A subsequent service or server restart will then run that binary with administrator privilege.

Related CVEs

Key Information

GHSA ID
GHSA-6pxp-6h5g-5389
Published
January 18, 2025 3:31 PM
Last Modified
January 18, 2025 3:31 PM
CVSS Score
5.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: September 15, 2025 6:32 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.