CVE Vulnerabilities

CVE-2016-9638

Published: Dec 02, 2016 | Modified: Jul 28, 2017
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

In BMC Patrol before 9.13.10.02, the binary listguests64 is configured with the setuid bit. However, when executing it, it will look for a binary named virsh using the PATH environment variable. The listguests64 program will then run virsh using root privileges. This allows local users to elevate their privileges to root.

Affected Software

Name Vendor Start Version End Version
Patrol Bmc * 9.13.10.01 (including)

References