{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2025-55116","assignerOrgId":"24a3c815-5f22-4d74-967a-30958d6466f4","state":"PUBLISHED","assignerShortName":"airbus","dateReserved":"2025-08-07T07:24:22.470Z","datePublished":"2025-09-16T12:22:23.865Z","dateUpdated":"2026-02-26T17:48:31.380Z"},"containers":{"cna":{"affected":[{"defaultStatus":"affected","product":"Control-M/Agent","vendor":"BMC","versions":[{"status":"unaffected","version":"9.0.21","versionType":"semver"},{"status":"unaffected","version":"9.0.20.100","versionType":"semver"},{"status":"affected","version":"9.0.20","versionType":"semver"},{"status":"affected","version":"9.0.19","versionType":"semver"},{"status":"affected","version":"9.0.18","versionType":"semver"}]}],"credits":[{"lang":"en","type":"finder","value":"Airbus SAS - Jean-Romain Garnier - seclab@airbus.com"},{"lang":"en","type":"analyst","value":"Airbus SAS - Mathieu Baudon - seclab@airbus.com"}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<div><div>A buffer overflow in the Control-M/Agent can lead to a local privilege escalation when an attacker has access to the system running the Agent.</div><div><span style=\"background-color: rgb(255, 255, 255);\">This vulnerability impacts the out-of-support Control-M/Agent versions 9.0.18 to 9.0.20 and potentially earlier unsupported versions.</span><br></div></div>"}],"value":"A buffer overflow in the Control-M/Agent can lead to a local privilege escalation when an attacker has access to the system running the Agent.\n\nThis vulnerability impacts the out-of-support Control-M/Agent versions 9.0.18 to 9.0.20 and potentially earlier unsupported versions."}],"metrics":[{"cvssV4_0":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"LOCAL","baseScore":9.3,"baseSeverity":"CRITICAL","privilegesRequired":"LOW","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"HIGH","subConfidentialityImpact":"HIGH","subIntegrityImpact":"HIGH","userInteraction":"NONE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H","version":"4.0","vulnAvailabilityImpact":"HIGH","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnerabilityResponseEffort":"NOT_DEFINED"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]},{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"LOCAL","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-121","description":"CWE-121 Stack-based Buffer Overflow","lang":"en","type":"CWE"}]}],"providerMetadata":{"orgId":"24a3c815-5f22-4d74-967a-30958d6466f4","shortName":"airbus","dateUpdated":"2025-09-16T12:22:23.865Z"},"references":[{"tags":["vendor-advisory"],"url":"https://bmcapps.my.site.com/casemgmt/sc_KnowledgeArticle?sfdcid=000442099"},{"tags":["mitigation"],"url":"https://bmcapps.my.site.com/casemgmt/sc_KnowledgeArticle?sfdcid=000441969"}],"source":{"defect":["CTM-4553"],"discovery":"EXTERNAL"},"title":"BMC Control-M/Agent buffer overflow local privilege escalation","x_generator":{"engine":"Vulnogram 0.2.0"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"id":"CVE-2025-55116","role":"CISA Coordinator","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"total"}],"version":"2.0.3","timestamp":"2025-09-17T03:55:51.769560Z"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-02-26T17:48:31.380Z"}}]}}