Fortra's Robot Schedule Enterprise Agent for Windows prior to version 3.04 is susceptible to privilege escalation. A low-privileged user can overwrite the service executable. When the service is restarted, the replaced binary runs with local system privileges, allowing a low-privileged user to gain elevated privileges.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-16055 Fortra's Robot Schedule Enterprise Agent for Windows prior to version 3.04 is susceptible to privilege escalation. A low-privileged user can overwrite the service executable. When the service is restarted, the replaced binary runs with local system privileges, allowing a low-privileged user to gain elevated privileges.
Fixes

Solution

Upgrade Robot Schedule Enterprise agents for Windows to version 3.04 or higher.


Workaround

No workaround given by the vendor.

History

Wed, 09 Apr 2025 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Fortra
Fortra robot Schedule
Microsoft
Microsoft windows
CPEs cpe:2.3:a:fortra:robot_schedule:*:*:*:*:enterprise:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Fortra
Fortra robot Schedule
Microsoft
Microsoft windows

cve-icon MITRE

Status: PUBLISHED

Assigner: Fortra

Published:

Updated: 2024-08-01T17:41:16.446Z

Reserved: 2024-01-05T23:59:37.995Z

Link: CVE-2024-0259

cve-icon Vulnrichment

Updated: 2024-08-01T17:41:16.446Z

cve-icon NVD

Status : Analyzed

Published: 2024-03-28T15:15:46.180

Modified: 2025-04-09T15:42:22.040

Link: CVE-2024-0259

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.