7.8
CVSSv3

CVE-2024-11220

CVSSv4: 8.5 | CVSSv3: 7.8 | CVSSv2: NA | VMScore: 950 | EPSS: 0.00025 | KEV: Not Included
Published: 06/12/2024 Updated: 06/12/2024

Vulnerability Summary

Privilege Escalation via RDLX File Execution in OAS Services

A local user with basic access on the server machine, who has credentials for the running OAS services, can create and run a report using an rdlx file directly on the server system. Any code within this rdlx file will execute with SYSTEM privileges. This leads to privilege escalation.

Vulnerability Trend