ZeroHour

CVE-2020-1712

CVSS 3.1
7.8 high
EPSS
<1%p38
Published
()
Modified
Description

A heap use-after-free vulnerability was found in systemd before version v245-rc1, where asynchronous Polkit queries are performed while handling dbus messages. A local unprivileged attacker can abuse this flaw to crash systemd services or potentially execute code and elevate their privileges, by sending specially crafted dbus messages.

Vendors
systemd projectredhatdebian
Products
systemd, ceph storage, discovery, migration toolkit, openshift container platform, enterprise linux, debian linux
Weakness
CWE-416
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.