A local low-level user on the server machine with credentials to the running OAS services can create and execute a report with an rdlx file on the server system itself. Any code within the rdlx file of the report executes with SYSTEM privileges, resulting in privilege escalation.
CVE ID: CVE-2024-11220
CVSS Base Severity: HIGH
CVSS Base Score: 7.8
Vendor: Open Automation Software
Product: Open Automation Software
EPSS Score: 0.04% (probability of being exploited)
EPSS Percentile: 5.17% (scored less or equal to compared to others)
EPSS Date: 2025-02-03 (when was this score calculated)