CVE-2016-9638: High severity bmc patrol agent vulnerability
In BMC Patrol before 9.13.10.02, the binary "listguests64" is configured with the setuid bit. However, when executing it, it will look for a binary named "virsh" using the PATH environment variable. The "listguests64" program will then run "virsh" using root privileges. This allows local users to elevate their privileges to root.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2016-9638?
CVE-2016-9638 has a medium severity rating due to its potential for local privilege escalation.
How do I fix CVE-2016-9638?
To fix CVE-2016-9638, remove the setuid bit from the listguests64 binary or upgrade to a patched version of BMC Patrol.
Who is affected by CVE-2016-9638?
CVE-2016-9638 affects users of BMC Patrol versions prior to 9.13.10.02.
What is the impact of exploiting CVE-2016-9638?
Exploiting CVE-2016-9638 allows local users to execute arbitrary commands with root privileges.
Is CVE-2016-9638 a zero-day vulnerability?
CVE-2016-9638 is not a zero-day vulnerability as it was publicly disclosed and has patches available.