# CVE-2024-51448

## Summary

- **CVE ID:** CVE-2024-51448
- **Severity:** MEDIUM
- **CVSS Score:** 6.7 (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H)
- **CWE:** CWE-277
- **Published:** Jan 18, 2025
- **Last Modified:** Mar 13, 2026

## Description

IBM Robotic Process Automation 21.0.0 through 21.0.7.17 and 23.0.0 through 23.0.18 could allow a local user to escalate their privileges. All files in the install inherit the file permissions of the parent directory and therefore a non-privileged user can substitute any executable for the nssm.exe service. A subsequent service or server restart will then run that binary with administrator privilege.

## Affected Products

- IBM — Robotic Process Automation (21.0.0)
- IBM — Robotic Process Automation (23.0.0)

## References

- [CNA](https://www.ibm.com/support/pages/node/7177586)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.15%
- **EPSS Percentile:** 4.5

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._