CVE Database
/

CVE-2016-9638

Back to search

CVE-2016-9638

Published: Dec 2, 2016

Modified: Aug 6, 2024

PUBLISHED

Description

In BMC Patrol before 9.13.10.02, the binary "listguests64" is configured with the setuid bit. However, when executing it, it will look for a binary named "virsh" using the PATH environment variable. The "listguests64" program will then run "virsh" using root privileges. This allows local users to elevate their privileges to root.

VendorProductVersions

n/a

n/a

affected
n/a

References

1037385
vdb-entry
x_refsource_SECTRACK
95009
vdb-entry
x_refsource_BID

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now