CVE-2018-15686
PoC —CVSS 3.1
7.8 high
EPSS
2%p82
Published
()
Modified
Description
A vulnerability in unit_deserialize of systemd allows an attacker to supply arbitrary state across systemd re-execution via NotifyAccess. This can be used to improperly influence systemd execution and possibly lead to root privilege escalation. Affected releases are systemd versions up to and including 239.
- Vendors
- canonicaldebiansystemd projectoracle
- Products
- ubuntu linux, debian linux, systemd, communications cloud native core network function cloud native environment
- Weakness
- CWE-502
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.