Описание
An issue was discovered in BMC Patrol Agent 9.0.10i. Weak execution permissions on the best1collect.exe SUID binary could allow an attacker to elevate his/her privileges to the ones of the "patrol" user by specially crafting a shared library .so file that will be loaded during execution.
Ссылки
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:bmc:patrol_agent:9.0.10i:*:*:*:*:*:*:*
EPSS
Процентиль: 38%
0.00165
Низкий
7.8 High
CVSS3
4.6 Medium
CVSS2
Дефекты
CWE-276
Связанные уязвимости
CVSS3: 7.8
github
больше 3 лет назад
An issue was discovered in BMC Patrol Agent 9.0.10i. Weak execution permissions on the best1collect.exe SUID binary could allow an attacker to elevate his/her privileges to the ones of the "patrol" user by specially crafting a shared library .so file that will be loaded during execution.
EPSS
Процентиль: 38%
0.00165
Низкий
7.8 High
CVSS3
4.6 Medium
CVSS2
Дефекты
CWE-276