CRITICAL🇵🇱 Wersja polska

CVE-2025-55116

CVSS 9.3v4.0pub. 2025-09-16upd. 2025-10-10

A buffer overflow in the Control-M/Agent can lead to a local privilege escalation when an attacker has access to the system running the Agent. This vulnerability impacts the out-of-support Control-M/Agent versions 9.0.18 to 9.0.20 and potentially earlier unsupported versions.

🤖 AI Analysis
How it works

The vulnerability is a stack-based buffer overflow in the Control-M/Agent component. An attacker with local access to the system running the Agent can exploit this vulnerability to overwrite critical memory structures. This leads to gaining control over the program execution flow and obtaining higher system privileges than originally granted to the attacker.

Impact

An attacker with local access to the system can perform privilege escalation and obtain elevated privileges, potentially across both the local system and related systems (high impact on confidentiality, integrity, and availability in the local and system context).

Mitigation & patch

The vendor indicates that vulnerable versions (9.0.18–9.0.20) are end-of-support and will not receive patches. Migration to a currently supported version of BMC Control-M/Agent is recommended. Detailed information is available in the vendor's knowledge base articles under references: sfdcid=000441969 and sfdcid=000442099. Until migration is completed, restrict local access to the system running the Agent to trusted, necessary accounts only.

Who is affected

BMC Control-M/Agent in versions 9.0.18 through 9.0.20 (out of vendor support) and potentially earlier unsupported versions.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Bmc Control M\/agent

    APP
    Bmc
    < 9.0.20.100
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
LPEMemory
CWE
References

Related vulnerabilities

CVE-2025-55109CRITICAL9.5PL ✓same product

BMC Control-M/Agent: Authentication Bypass przez niezabezpieczony keystore

CVE-2025-55113CRITICAL9.5PL ✓same product

BMC Control-M/Agent: Bypass ACL przez NULL byte w certyfikacie klienta

CVE-2025-55115CRITICAL9.3PL ✓same product

Path traversal w BMC Control-M/Agent prowadzący do privilege escalation

CVE-2025-55112HIGH7.6same product

Out-of-support Control-M/Agent versions 9.0.18 to 9.0.20 (and potentially earlier unsupported versions) that a...

CVE-2025-55111MEDIUM5.7same product

Certain files with overly permissive permissions were identified in the out-of-support Control-M/Agent version...