PT-2024-12603 · Alt N Technologies · Automationmanager.Agentservice.Exe

Andrew Oliveau

·

Published

2024-05-02

·

Updated

2025-07-22

·

CVE-2023-37244

CVSS v3.1

7.0

High

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions AutomationManager.AgentService.exe versions prior to 2.91.0.0
Description The affected AutomationManager.AgentService.exe application contains a TOCTOU race condition vulnerability that allows standard users to create a pseudo-symlink at C:ProgramDataN-Able TechnologiesAutomationManagerTemp, which could be leveraged by an attacker to manipulate the process into performing arbitrary file deletions.
Recommendations For versions prior to 2.91.0.0, upgrade to version 2.91.0.0 to resolve the issue. As a temporary workaround, consider restricting access to the Temp directory at C:ProgramDataN-Able TechnologiesAutomationManagerTemp to minimize the risk of exploitation.

Fix

Race Condition

Weakness Enumeration

Related Identifiers

CVE-2023-37244

Affected Products

Automationmanager.Agentservice.Exe