7.8
CVE-2024-1605
- EPSS 0.2%
- Veröffentlicht 18.03.2024 10:15:20
- Zuletzt bearbeitet 06.03.2025 14:25:09
- Quelle cvd@cert.pl
- CVE-Watchlists
- Unerledigt
DLL side-loading in BMC Control-M
BMC Control-M branches 9.0.20 and 9.0.21 upon user login load all Dynamic Link Libraries (DLL) from a directory that grants Write and Read permissions to all users. Leveraging it leads to loading of a potentially malicious libraries, which will execute with the application's privileges. Fix for 9.0.20 branch was released in version 9.0.20.238. Fix for 9.0.21 branch was released in version 9.0.21.201.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.2% | 0.103 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
|
| cvd@cert.pl | 6.6 | 1.8 | 4.7 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L
|
CWE-276 Incorrect Default Permissions
During installation, installed file permissions are set to allow anyone to modify those files.
https://www.bmc.com/it-solutions/control-m.html
https://cert.pl/en/posts/2024/03/CVE-2024-1604
https://cert.pl/posts/2024/03/CVE-2024-1604