PT-2024-12603 · Alt N Technologies · Automationmanager.Agentservice.Exe
Andrew Oliveau
·
Published
2024-05-02
·
Updated
2025-07-22
·
CVE-2023-37244
CVSS v3.1
7.0
High
| Vector | AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
AutomationManager.AgentService.exe versions prior to 2.91.0.0
Description
The affected AutomationManager.AgentService.exe application contains a TOCTOU race condition vulnerability that allows standard users to create a pseudo-symlink at C:ProgramDataN-Able TechnologiesAutomationManagerTemp, which could be leveraged by an attacker to manipulate the process into performing arbitrary file deletions.
Recommendations
For versions prior to 2.91.0.0, upgrade to version 2.91.0.0 to resolve the issue. As a temporary workaround, consider restricting access to the Temp directory at C:ProgramDataN-Able TechnologiesAutomationManagerTemp to minimize the risk of exploitation.
Fix
Race Condition
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Automationmanager.Agentservice.Exe