Description
The affected AutomationManager.AgentService.exe application contains a TOCTOU race condition vulnerability that allows standard users to create a pseudo-symlink at C:\ProgramData\N-Able Technologies\AutomationManager\Temp, which could be leveraged by an attacker to manipulate the process into performing arbitrary file deletions. We recommend upgrading to version 2.91.0.0
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-41164 | The affected AutomationManager.AgentService.exe application contains a TOCTOU race condition vulnerability that allows standard users to create a pseudo-symlink at C:\ProgramData\N-Able Technologies\AutomationManager\Temp, which could be leveraged by an attacker to manipulate the process into performing arbitrary file deletions. We recommend upgrading to version 2.91.0.0 |
References
History
Tue, 22 Jul 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Microsoft
Microsoft windows N-able N-able automation Manager |
|
| CPEs | cpe:2.3:a:n-able:automation_manager:*:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* |
|
| Vendors & Products |
Microsoft
Microsoft windows N-able N-able automation Manager |
Status: PUBLISHED
Assigner: Google
Published:
Updated: 2024-08-02T17:09:33.280Z
Reserved: 2023-06-29T10:33:40.828Z
Link: CVE-2023-37244
Updated: 2024-08-02T17:09:33.280Z
Status : Analyzed
Published: 2024-05-02T14:15:09.410
Modified: 2025-07-22T21:02:14.057
Link: CVE-2023-37244
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD