In BMC Patrol before 9.13.10.02, the binary listguests64 is configured with the setuid bit. However, when executing it, it will look for a binary named virsh using the PATH environment variable. The listguests64 program will then run virsh using root privileges. This allows local users to elevate their privileges to root.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Patrol | Bmc | * | 9.13.10.01 (including) |