#VU111160 Untrusted search path in Apache Tomcat - CVE-2025-49124

 

#VU111160 Untrusted search path in Apache Tomcat - CVE-2025-49124

Published: June 16, 2025


Vulnerability identifier: #VU111160
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2025-49124
CWE-ID: CWE-426
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Apache Tomcat
Software vendor:
Apache Foundation

Description

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to usage of an untrusted search path in the application's installer on Windows. A local user can place a malicious binary icacls.exe into the current working directory of the installer file end execute arbitrary code with elevated privileges.

Note, the vulnerability affects Windows systems only. 


Remediation

Install updates from vendor's website.

External links