CVE-2019-17043: High severity bmc patrol perform agent vulnerability
An issue was discovered in BMC Patrol Agent 9.0.10i. Weak execution permissions on the best1collect.exe SUID binary could allow an attacker to elevate his/her privileges to the ones of the "patrol" user by specially crafting a shared library .so file that will be loaded during execution.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-17043?
CVE-2019-17043 is a vulnerability discovered in BMC Patrol Agent 9.0.10i that allows an attacker to elevate their privileges by crafting a malicious shared library file.
How severe is CVE-2019-17043?
CVE-2019-17043 has a severity score of 7.8, indicating a high severity.
How can an attacker exploit CVE-2019-17043?
An attacker can exploit CVE-2019-17043 by crafting a specially crafted shared library .so file and executing it through the vulnerable best1collect.exe binary.
Which versions of BMC Patrol Agent are affected by CVE-2019-17043?
CVE-2019-17043 affects BMC Patrol Agent version 9.0.10i.
Are there any references for CVE-2019-17043?
Yes, you can find references for CVE-2019-17043 at the following links: [1](https://github.com/blogresponder/BMC-Patrol-Agent-local-root-privilege-escalation), [2](https://twitter.com/whira_wr).