CVE-2025-55116
8.8BMC · Control-M/Agent
A stack-based buffer overflow in the BMC Control-M/Agent allows local authenticated users to escalate privileges to the system level.
Executive summary
A critical buffer overflow vulnerability in the BMC Control-M/Agent enables local attackers to achieve full system-level privilege escalation.
Vulnerability
This is a stack-based buffer overflow (CWE-121) occurring within the Control-M/Agent software. An attacker with local access and low privileges can trigger this flaw to execute arbitrary code with elevated system permissions.
Business impact
The ability for a local user to escalate to system-level privileges poses a severe risk to the entire enterprise environment. Successful exploitation grants an attacker full control over the host system, facilitating data theft, installation of persistent backdoors, or lateral movement into the wider network. With a CVSS score of 8.8, this vulnerability represents a high-severity threat that necessitates immediate attention to prevent total system compromise.
Remediation
Immediate Action: Update the affected BMC Control-M/Agent installations to version 9.0.20.100 or 9.0.21, as these versions contain the necessary security patches.
Proactive Monitoring: Audit local system logs for unusual process execution or unauthorized attempts to access agent-related binaries that might indicate an exploitation attempt.
Compensating Controls: Implement strict principle-of-least-privilege access controls on all systems running the Control-M/Agent to minimize the pool of users capable of interacting with the vulnerable component.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the potential for full system compromise, administrators must prioritize upgrading the BMC Control-M/Agent to the specified fixed versions. Environments currently running out-of-support versions should expedite migration to supported releases, as the vulnerability is confirmed to impact legacy configurations that may no longer receive standard security maintenance.
More BMC CVEs
Sources
Originally found and disclosed by Airbus SAS - Jean-Romain Garnier - seclab@airbus.com, with Airbus SAS - Mathieu Baudon - seclab@airbus.com (analyst), per the CVE Program record.