CVE-2024-11220

A local low-level user on the server machine with credentials to the running OAS services can create and execute a report with an rdlx file on the server system itself. Any code within the rdlx file of the report executes with SYSTEM privileges, resulting in privilege escalation.
Configurations

Configuration 1 (hide)

cpe:2.3:a:openautomationsoftware:open_automation_software:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2024-12-06 18:15

Updated : 2025-01-23 16:54


NVD link : CVE-2024-11220

Mitre link : CVE-2024-11220

CVE.ORG link : CVE-2024-11220


JSON object : View

Products Affected

openautomationsoftware

  • open_automation_software
CWE
CWE-279

Incorrect Execution-Assigned Permissions

CWE-732

Incorrect Permission Assignment for Critical Resource