Description
A buffer overflow in the Control-M/Agent can lead to a local privilege escalation when an attacker has access to the system running the Agent. This vulnerability impacts the out-of-support Control-M/Agent versions 9.0.18 to 9.0.20 and potentially earlier unsupported versions.
Problem types
CWE-121 Stack-based Buffer Overflow
Product status
9.0.21 (semver)
9.0.20.100 (semver)
9.0.20 (semver)
9.0.19 (semver)
9.0.18 (semver)
Credits
Airbus SAS - Jean-Romain Garnier - seclab@airbus.com 
Airbus SAS - Mathieu Baudon - seclab@airbus.com 
References
bmcapps.my.site.com/.../sc_KnowledgeArticle?sfdcid=000442099 
bmcapps.my.site.com/.../sc_KnowledgeArticle?sfdcid=000441969