Regarding Windows Service Weak Permissions detected vulnerabilityVulnerability related to weak file permissions on the UiPath service exe

Description

Hi All,

We have the UiPath Studio installed on our system & we are getting the vulnerability risk due to weak file permissions

C:\Program Files\UiPath\Studio\UiPath.UpdateService.Worker.exe
C:\Program Files\UiPath\Studio\UiPath.RobotJs.ServiceHost.exe

The recommended solution is to update the NTFS permissions to ensure:

Administrators / SYSTEM: Full Control
Users: Read & Execute only (no write or modify permissions)

The user has two permissions: Modify and Read & Execute.
The Modify permission needs to be removed.

Can someone help here?

Link

Date

2026-01-04

@ugnx_middleware

Welcome to the community

Is it a community edition?

Service host might need higher but updateservice can be controlled if its enterprise

cheers

It’s a community version

Enterprise customers (assuming you are one based on the issue described) are recommended to use the LTS support versions. Not sure if they have the same issue, but I’d suggest installing that and seeing if that works.

It does mean we need to wait longer for features of course, which is tough when they keep making cool new things to try, but we cannot skip some governance stuff sadly.