CVE-2025-49124: Apache Tomcat: exe side-loading via icalcs.exe in Tomcat installer for Windows
Untrusted Search Path vulnerability in Apache Tomcat installer for Windows. During installation, the Tomcat installer for Windows used icacls.exe without specifying a full path.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0 through 10.1.41, from 9.0.23 through 9.0.105. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 through 8.5.100 and 7.0.95 through 7.0.109. Other EOL versions may also be affected.
Users are recommended to upgrade to version 11.0.8, 10.1.42 or 9.0.106, which fix the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Tomcat (Windows installer)to a version that resolves this vulnerability.Fixed in 11.0.8 - Upgrade
Upgrade
Apache Tomcat (Windows installer)to a version that resolves this vulnerability.Fixed in 10.1.42 - Upgrade
Upgrade
Apache Tomcat (Windows installer)to a version that resolves this vulnerability.Fixed in 9.0.106 - Upgrade
Upgrade
Apache Tomcat (Windows installer)to a version that resolves this vulnerability.Fixed in 8.5.100 - Upgrade
Upgrade
Apache Tomcat (Windows installer)to a version that resolves this vulnerability.Fixed in 7.0.109
Event History
Frequently Asked Questions
What is the severity of CVE-2025-49124?
CVE-2025-49124 is classified as a medium severity vulnerability due to the potential for local privilege escalation during the installation process.
How do I fix CVE-2025-49124?
To fix CVE-2025-49124, upgrade Apache Tomcat to the latest version that addresses the untrusted search path issue.
Which versions of Apache Tomcat are affected by CVE-2025-49124?
CVE-2025-49124 affects Apache Tomcat versions 11.0.0-M1 through 11.0.7, 10.1.0 through 10.1.41, and 9.0.23 and later.
What is the main issue with CVE-2025-49124?
The main issue with CVE-2025-49124 is that the Tomcat installer for Windows improperly uses icacls.exe without a full path, creating a potential security risk.
Can CVE-2025-49124 be exploited remotely?
CVE-2025-49124 cannot be exploited remotely as it requires local access to the system during installation.