
Cloud Vulnerability DB
A community-led vulnerabilities database
BMC Control-M branches 9.0.20 and 9.0.21 contain a DLL side-loading vulnerability (CVE-2024-1605) discovered and disclosed on March 18, 2024. The vulnerability affects the application's user login process in versions prior to 9.0.20.238 (for 9.0.20 branch) and 9.0.21.201 (for 9.0.21 branch) (CERT Advisory).
The vulnerability occurs when the application loads all Dynamic Link Libraries (DLL) from a directory that grants Write and Read permissions to all users upon user login. This incorrect default permission setting (CWE-276) allows potentially malicious libraries to be loaded and executed with the application's privileges. The vulnerability has been assigned a CVSS v3.1 base score of 6.6 (Medium) with the vector string CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L (NVD).
When exploited, this vulnerability allows the execution of malicious libraries with the application's privileges, potentially compromising system security. The impact includes high confidentiality breach potential, with low integrity and availability impacts (CERT Advisory).
The vulnerability requires local access and user interaction to be exploited. An attacker can leverage the incorrect directory permissions to place malicious DLL files that will be loaded by the application when a user logs in (NVD).
The vulnerability has been fixed in version 9.0.20.238 for the 9.0.20 branch and version 9.0.21.201 for the 9.0.21 branch. Users are advised to upgrade to these or later versions to address the security issue (CERT Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."