Untrusted search path in Apache Tomcat - CVE-2025-49124

 

Untrusted search path in Apache Tomcat - CVE-2025-49124

Published: June 16, 2025


Vulnerability identifier: #VU111160
CSH Severity: Low
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-49124
CWE-ID: CWE-426
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to usage of an untrusted search path in the application's installer on Windows. A local user can place a malicious binary icacls.exe into the current working directory of the installer file end execute arbitrary code with elevated privileges.

Note, the vulnerability affects Windows systems only. 


Affected software

Apache Tomcat
Netcool Operations Insight
EasyApache
IBM Engineering Requirements Management DOORS Next
CICS Transaction Gateway for Multiplatforms
CICS Transaction Gateway Desktop Edition
Storage Protect Plus Server

How to mitigate CVE-2025-49124

Install updates from vendor's website.

Apache Tomcat - addressed in versions 9.0.106, 10.1.42, 11.0.8
Netcool Operations Insight - update to 1.6.15
EasyApache - update to 4 25-20
IBM Engineering Requirements Management DOORS Next - update to 9.7.2.11
Storage Protect Plus Server - update to 10.1.18

External References

Related Security Bulletins