CVE-2018-20735 describes a privilege escalation vulnerability in BMC PATROL Agent through version 11.3.01. The PatrolCli application, by default, only validates user passwords without verifying network permissions, allowing a low-privileged domain user to execute commands as SYSTEM on a high-value target like a domain controller. This vulnerability carries a CVSS score of 7.8 (High) due to its low attack complexity and significant impact on confidentiality, integrity, and availability. While not listed in CISA KEV, a Metasploit module exists for exploitation, and its EPSS score indicates a higher than average exploitability probability. Despite the vendor disputing the severity, this flaw presents a critical risk for lateral movement and domain administrator escalation within affected Windows Active Directory environments.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 11.3.01CPE matchmatch criteria | cpe:2.3:a:bmc:patrol_agent:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.