ZeroHour

CVE-2022-23220

PoC
CVSS 3.1
7.8 high
EPSS
<1%p43
Published
()
Modified
Description

USBView 2.1 before 2.2 allows some local users (e.g., ones logged in via SSH) to execute arbitrary code as root because certain Polkit settings (e.g., allow_any=yes) for pkexec disable the authentication requirement. Code execution can, for example, use the --gtk-module option. This affects Ubuntu, Debian, and Gentoo.

Vendors
usbview project
Products
usbview
Weakness
CWE-306
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.