CVE-2024-1605
Control-M vulnerability analysis and mitigation

Overview

BMC Control-M branches 9.0.20 and 9.0.21 contain a DLL side-loading vulnerability (CVE-2024-1605) discovered and disclosed on March 18, 2024. The vulnerability affects the application's user login process in versions prior to 9.0.20.238 (for 9.0.20 branch) and 9.0.21.201 (for 9.0.21 branch) (CERT Advisory).

Technical details

The vulnerability occurs when the application loads all Dynamic Link Libraries (DLL) from a directory that grants Write and Read permissions to all users upon user login. This incorrect default permission setting (CWE-276) allows potentially malicious libraries to be loaded and executed with the application's privileges. The vulnerability has been assigned a CVSS v3.1 base score of 6.6 (Medium) with the vector string CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L (NVD).

Impact

When exploited, this vulnerability allows the execution of malicious libraries with the application's privileges, potentially compromising system security. The impact includes high confidentiality breach potential, with low integrity and availability impacts (CERT Advisory).

Exploitability

The vulnerability requires local access and user interaction to be exploited. An attacker can leverage the incorrect directory permissions to place malicious DLL files that will be loaded by the application when a user logs in (NVD).

Mitigation and workarounds

The vulnerability has been fixed in version 9.0.20.238 for the 9.0.20 branch and version 9.0.21.201 for the 9.0.21 branch. Users are advised to upgrade to these or later versions to address the security issue (CERT Advisory).

Additional resources


SourceThis report was generated using AI

Related Control-M vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2023-39122CRITICAL9.8
  • Control-M logoControl-M
  • cpe:2.3:a:bmc:control-m
NoYesJul 31, 2023
CVE-2023-26550CRITICAL9.8
  • Control-M logoControl-M
  • cpe:2.3:a:bmc:control-m
NoYesFeb 25, 2023
CVE-2024-1605HIGH7.8
  • Control-M logoControl-M
  • cpe:2.3:a:bmc:control-m
NoYesMar 18, 2024
CVE-2024-1604MEDIUM6.8
  • Control-M logoControl-M
  • cpe:2.3:a:bmc:control-m
NoYesMar 18, 2024
CVE-2024-1606MEDIUM5.4
  • Control-M logoControl-M
  • cpe:2.3:a:bmc:control-m
NoYesMar 18, 2024

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management