NA

CVE-2023-37244

Published: 02/05/2024 Updated: 02/05/2024

Vulnerability Summary

The affected AutomationManager.AgentService.exe application contains a TOCTOU race condition vulnerability that allows standard users to create a pseudo-symlink at C:\ProgramData\N-Able Technologies\AutomationManager\Temp, which could be leveraged by an malicious user to manipulate the process into performing arbitrary file deletions. We recommend upgrading to version 2.91.0.0