An issue was discovered in BMC Patrol Agent 9.0.10i. Weak execution permissions on the best1collect.exe SUID binary could allow an attacker to elevate his/her privileges to the ones of the "patrol" user by specially crafting a shared library .so file that will be loaded during execution.
oryginał ENCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HBmc Patrol Agent
APPBmc9.0.10i
Powiązane podatności
BMC Patrol Agent — zdalne wykonanie kodu przez niezabezpieczoną konfigurację SNMP
BMC PATROL Agent — statyczny klucz szyfrowania umożliwia kradzież poświadczeń
BMC PATROL Agent through 20.08.00 allows local privilege escalation via vectors involving pconfig +RESTART -ho...
An issue was discovered in BMC Patrol Agent 9.0.10i. Weak execution permissions on the PatrolAgent SUID binary...
An issue was discovered in BMC PATROL Agent through 11.3.01. It was found that the PatrolCli application can a...