CVSS v3
7.8
HIGH
EPSS Score
38.0 %
exploit probability
CISA KEV
No
known exploited
Exploitation
—
SSVC status
Description
An issue was discovered in BMC PATROL Agent through 11.3.01. It was found that the PatrolCli application can allow for lateral movement and escalation of privilege inside a Windows Active Directory environment. It was found that by default the PatrolCli / PATROL Agent application only verifies if the password provided for the given username is correct; it does not verify the permissions of the user on the network. This means if you have PATROL Agent installed on a high value target (domain controller), you can use a low privileged domain user to authenticate with PatrolCli and then connect to the domain controller and run commands as SYSTEM. This means any user on a domain can escalate to domain admin through PATROL Agent. NOTE: the vendor disputes this because they believe it is adequate to prevent this escalation by means of a custom, non-default configuration
Technical details
- Published
- 2019-01-17
- Exploit-DB
- EDB-46556
Frequently asked questions
What is CVE-2018-20735?
An issue was discovered in BMC PATROL Agent through 11.3.01. It was found that the PatrolCli application can allow for lateral movement and escalation of privilege inside a Windows Active Directory environment. It was found that by default the PatrolCli / PATROL Agent application only verifies if the password provided for the given username is correct; it does not verify the permissions of the user on the network. This means if you have PATROL Agent installed on a high value target (domain controller), you can use a low privileged domain user to authenticate with PatrolCli and then connect to the domain controller and run commands as SYSTEM. This means any user on a domain can escalate to domain admin through PATROL Agent. NOTE: the vendor disputes this because they believe it is adequate to prevent this escalation by means of a custom, non-default configuration
Is CVE-2018-20735 actively exploited?
Active exploitation of CVE-2018-20735 has not been confirmed. The EPSS score is 38.0%, indicating the estimated probability of exploitation in the next 30 days.
What is the CVSS score for CVE-2018-20735?
CVE-2018-20735 has a CVSS v3 base score of 7.8 (HIGH severity).
Is CVE-2018-20735 affecting your environment?
Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.
No credit card required · 500 free checks/month · Free API key
Other 2018 vulnerabilities worth triaging
Ranked by exploit probability (EPSS).