CVE-2016-9638
 
Severity Score
7.8
*CVSS v3
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
1
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
In BMC Patrol before 9.13.10.02, the binary "listguests64" is configured with the setuid bit. However, when executing it, it will look for a binary named "virsh" using the PATH environment variable. The "listguests64" program will then run "virsh" using root privileges. This allows local users to elevate their privileges to root.
En BMC Patrol en versiones anteriores a 9.13.10.02 el binario "listguests64" está configurado con el bit setuid. Sin embargo, cuando se ejecuta, buscará un binario llamado "virsh" usando la variable de entorno PATH. El programa "listguests64" ejecutará entonces "virsh" usando los privilegios de root. Esto permite a usuarios locales elevar sus privilegios a root.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2016-11-24 CVE Reserved
- 2016-12-02 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-06 CVE Updated
- 2024-08-06 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-264: Permissions, Privileges, and Access Controls
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/95009 | Third Party Advisory | |
http://www.securitytracker.com/id/1037385 | Vdb Entry |
URL | Date | SRC |
---|---|---|
http://www.nes.fr/securitylab/index.php/2016/12/02/privilege-escalation-on-bmc-patrol | 2024-08-06 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Bmc Search vendor "Bmc" | Patrol Search vendor "Bmc" for product "Patrol" | <= 9.13.10.01 Search vendor "Bmc" for product "Patrol" and version " <= 9.13.10.01" | - |
Affected
|