CVE-2025-55115

8.8

BMC · Control-M/Agent

A path traversal vulnerability in the BMC Control-M/Agent allows local users to escalate privileges on the host system.

Executive summary

A path traversal vulnerability in BMC Control-M/Agent versions 9.0.18 through 9.0.20 allows authenticated local users to escalate privileges to a higher level, posing a significant risk of system compromise.

Vulnerability

This vulnerability is a relative path traversal (CWE-23) that permits an attacker with local, low-privileged access to manipulate file paths, resulting in local privilege escalation. The vulnerability requires the attacker to already have local access to the system running the Agent.

Business impact

The ability to perform local privilege escalation grants an attacker unauthorized control over the host system, which could lead to full system compromise, data exfiltration, or the disruption of critical business workflows managed by Control-M. With a CVSS score of 8.8, this flaw is categorized as High, reflecting the severe potential impact on confidentiality, integrity, and availability if a local attacker successfully exploits the vulnerability to gain elevated permissions.

Remediation

Immediate Action: Upgrade all instances of BMC Control-M/Agent to version 9.0.20.100 or 9.0.21 to resolve the path traversal flaw.

Proactive Monitoring: Audit system logs for unexpected file access patterns or unauthorized attempts to execute commands using elevated privileges by local service accounts.

Compensating Controls: Implement strict file system permissions and least-privilege access controls on the host operating system to restrict the ability of local users to interact with sensitive agent directories.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Organizations utilizing affected versions of the BMC Control-M/Agent should prioritize upgrading their software to the provided fixed versions immediately. Given the potential for full privilege escalation, failure to patch could allow an attacker with limited local access to gain total control over the affected infrastructure.

More BMC CVEs

Sources

Originally found and disclosed by Airbus SAS - Jean-Romain Garnier - seclab@airbus.com, per the CVE Program record.