2024-10-10 18:03:19 +00:00

68 lines
2.5 KiB
JSON

{
"id": "CVE-2024-1605",
"sourceIdentifier": "cvd@cert.pl",
"published": "2024-03-18T10:15:20.583",
"lastModified": "2024-10-10T16:15:08.220",
"vulnStatus": "Awaiting Analysis",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "BMC Control-M branches 9.0.20 and 9.0.21 upon user login load all Dynamic Link Libraries (DLL) from a directory that grants Write and Read permissions to all users. Leveraging it leads to loading of a potentially malicious libraries, which will execute with the application's privileges. \n\n\n\n\n\nFix for 9.0.20 branch was released in version 9.0.20.238.\u00a0Fix for 9.0.21 branch was released in version 9.0.21.201."
},
{
"lang": "es",
"value": "BMC Control-M ramificaciones 9.0.20 y 9.0.21 al iniciar sesi\u00f3n el usuario carga todas las librer\u00edas de v\u00ednculos din\u00e1micos (DLL) desde un directorio que otorga permisos de escritura y lectura a todos los usuarios. Aprovecharlo conduce a la carga de librer\u00edas potencialmente maliciosas, que se ejecutar\u00e1n con los privilegios de la aplicaci\u00f3n. La soluci\u00f3n para la rama 9.0.20 se lanz\u00f3 en la versi\u00f3n 9.0.20.238. La soluci\u00f3n para la rama 9.0.21 se lanz\u00f3 en la versi\u00f3n 9.0.21.201."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "cvd@cert.pl",
"type": "Secondary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L",
"attackVector": "LOCAL",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "REQUIRED",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "LOW",
"availabilityImpact": "LOW",
"baseScore": 6.6,
"baseSeverity": "MEDIUM"
},
"exploitabilityScore": 1.8,
"impactScore": 4.7
}
]
},
"weaknesses": [
{
"source": "cvd@cert.pl",
"type": "Secondary",
"description": [
{
"lang": "en",
"value": "CWE-276"
}
]
}
],
"references": [
{
"url": "https://cert.pl/en/posts/2024/03/CVE-2024-1604",
"source": "cvd@cert.pl"
},
{
"url": "https://cert.pl/posts/2024/03/CVE-2024-1604",
"source": "cvd@cert.pl"
},
{
"url": "https://www.bmc.com/it-solutions/control-m.html",
"source": "cvd@cert.pl"
}
]
}