Critical Infrastructure Sectors: Critical Manufacturing
Privilege Escalation via RDLX File Execution in OAS Services
A local user with basic access on the server machine, who has credentials for the running OAS services, can create and run a report using an rdlx file directly on the server system. Any code within this rdlx file will execute with SYSTEM privileges. This leads to privilege escalation.