Description
Barracuda RMM versions prior to 2025.2.2 contain a privilege escalation vulnerability that allows local attackers to gain SYSTEM-level privileges by exploiting overly permissive filesystem ACLs on the C:\Windows\Automation directory. Attackers can modify existing automation content or place attacker-controlled files in this directory, which are then executed under the NT AUTHORITY\SYSTEM account during routine automation cycles, typically succeeding within the next execution cycle.
Problem types
CWE-732 Incorrect Permission Assignment for Critical Resource
Product status
Any version before 2025.2.2
References
download.mw-rmm.barracudamsp.com/.../RN_BRMM_2025.2.2_EN.pdf
www.vulncheck.com/...tion-via-insecure-directory-permissions