CVE-2024-1605 MEDIUM

CVE-2024-1605: DLL side-loading in BMC Control-M

Vendor Bmc
Product Control-M
Weakness CWE-276
Published March 18, 2024
Last update April 10, 2025

CVSS base score

6.6/10
Attack vector Local
Attack complexity Low
Privileges required None
User interaction Required
Confidentiality High
Integrity Low

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L

What the vulnerability does

01Description

BMC Control-M branches 9.0.20 and 9.0.21 upon user login load all Dynamic Link Libraries (DLL) from a directory that grants Write and Read permissions to all users. Leveraging it leads to loading of a potentially malicious libraries, which will execute with the application's privileges. Fix for 9.0.20 branch was released in version 9.0.20.238. Fix for 9.0.21 branch was released in version 9.0.21.201.

Key dates

02Disclosure timeline

March 18, 2024 CVE published
April 10, 2025 Record updated