#VU111160 Untrusted search path in Apache Tomcat - CVE-2025-49124
Published: June 16, 2025
Apache Tomcat
Apache Foundation
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to usage of an untrusted search path in the application's installer on Windows. A local user can place a malicious binary icacls.exe into the current working directory of the installer file end execute arbitrary code with elevated privileges.
Note, the vulnerability affects Windows systems only.
Remediation
External links
- https://tomcat.apache.org/security-11.html#Fixed_in_Apache_Tomcat_11.0.8
- https://tomcat.apache.org/security-10.html#Fixed_in_Apache_Tomcat_10.1.42
- https://tomcat.apache.org/security-9.html#Fixed_in_Apache_Tomcat_9.0.106
- https://github.com/apache/tomcat/commit/c56456cda8151c9504dfb7985700824559d769a7
- https://github.com/apache/tomcat/commit/e0e07812224d327a321babb554f5a5758d30cc49
- https://github.com/apache/tomcat/commit/28726cc2e63bed68771f5eb0f65a78dc7080571823
- https://lists.apache.org/thread/p201jp4to0nr4ky9h3j97ywk2zqv185m