PT-2026-24809 · Microsoft+1 · Intune+2

Khronosd

·

Publicado

2026-03-11

·

Atualizado

2026-04-15

·

CVE-2026-31979

CVSS v3.1

8.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Himmelblau versions prior to 3.1.0 Himmelblau versions prior to 2.3.8
Description Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. The himmelblaud-tasks daemon, running as root, writes Kerberos cache files under /tmp/krb5cc <uid> without symlink protections. The PrivateTmp setting was removed from the daemon’s systemd hardening, exposing it to the host /tmp. A local user can exploit this through symlink attacks to overwrite arbitrary files, potentially achieving local privilege escalation. This is a Time-of-Check to Time-of-Use (TOCTOU) vulnerability where a Kerberos cache file can be swapped for a symlink to /etc/shadow, allowing an unprivileged user to gain control of system credentials.
Recommendations Versions prior to 3.1.0: Update to version 3.1.0. Versions prior to 2.3.8: Update to version 2.3.8.

Exploit

Correção

LPE

Link Following

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-31979
GHSA-44WM-Q286-GHQ3
OPENSUSE-FU-2026:20453-1
OPENSUSE-SU-2026:10328-1
SUSE-FU-2026:20990-1
SUSE-SU-2026:1361-1

Produtos afetados

Himmelblau
Intune
Azure Entra Id