CVE-2025-49124 | Apache Tomcat up to 9.0.105/10.1.41/11.0.7 on Windows Installer icacls.exe untrusted search path (EUVD-2025-18410 / Nessus ID 240060)
A vulnerability, which was classified as problematic, has been found in Apache Tomcat up to 9.0.105/10.1.41/11.0.7 on Windows. Affected is an unknown function of the file icacls.exe of the component Installer. Performing manipulation results in untrusted search path.
This vulnerability was named CVE-2025-49124. The attack needs to be approached locally. There is no available exploit.
It is advisable to upgrade the affected component.