First published: Mon Oct 14 2019(Updated: )
An issue was discovered in BMC Patrol Agent 9.0.10i. Weak execution permissions on the best1collect.exe SUID binary could allow an attacker to elevate his/her privileges to the ones of the "patrol" user by specially crafting a shared library .so file that will be loaded during execution.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Bmc Patrol Agent | =9.0.10i |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-17043 is a vulnerability discovered in BMC Patrol Agent 9.0.10i that allows an attacker to elevate their privileges by crafting a malicious shared library file.
CVE-2019-17043 has a severity score of 7.8, indicating a high severity.
An attacker can exploit CVE-2019-17043 by crafting a specially crafted shared library .so file and executing it through the vulnerable best1collect.exe binary.
CVE-2019-17043 affects BMC Patrol Agent version 9.0.10i.
Yes, you can find references for CVE-2019-17043 at the following links: [1](https://github.com/blogresponder/BMC-Patrol-Agent-local-root-privilege-escalation), [2](https://twitter.com/whira_wr).