PT-2019-14922 · Bmc · Bmc Patrol Agent
Published
2019-10-14
·
Updated
2019-10-18
·
CVE-2019-17044
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
BMC Patrol Agent version 9.0.10i
Description
An issue was discovered that allows an attacker with "patrol" privileges to elevate their privileges to those of the "root" user. This can be achieved by specially crafting a shared library .so file that will be loaded during execution, taking advantage of weak execution permissions on the PatrolAgent SUID binary.
Recommendations
For BMC Patrol Agent version 9.0.10i, consider restricting access to the PatrolAgent SUID binary to prevent exploitation. Additionally, monitor for any suspicious shared library .so files that could be used to elevate privileges. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Incorrect Default Permissions
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bmc Patrol Agent