CVE-2019-17044: High severity bmc patrol perform agent vulnerability
Published Oct 14, 2019
·Updated
An issue was discovered in BMC Patrol Agent 9.0.10i. Weak execution permissions on the PatrolAgent SUID binary could allow an attacker with "patrol" privileges to elevate his/her privileges to the ones of the "root" user by specially crafting a shared library .so file that will be loaded during execution.
Affected Software
2 affected components
BMC PATROL Agent=9.0.10i
Linux Linux kernel
Remediation
Event History
Oct 14, 2019
CVE Published
via MITRE·04:47 PM
Data Sourced
via MITRE·04:47 PM
Description
Frequently Asked Questions
1
What is CVE-2019-17044?
CVE-2019-17044 is a vulnerability in BMC Patrol Agent 9.0.10i that allows an attacker with "patrol" privileges to elevate their privileges to the root user.
2
How severe is CVE-2019-17044?
CVE-2019-17044 has a severity score of 7.8 out of 10.
3
How does CVE-2019-17044 affect BMC Patrol Agent?
CVE-2019-17044 affects BMC Patrol Agent version 9.0.10i.
4
Is Linux kernel vulnerable to CVE-2019-17044?
No, Linux kernel is not vulnerable to CVE-2019-17044.
5
How can I fix CVE-2019-17044?
To fix CVE-2019-17044, users of BMC Patrol Agent need to apply the security patch provided by BMC.