PT-2022-15906 · Canonical+1 · Ubuntu+1
Matthias Gerstner
·
Published
2022-01-21
·
Updated
2024-06-15
·
CVE-2022-23220
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
USBView versions 2.1 through 2.1
Description
The issue allows local users, such as those logged in via SSH, to execute arbitrary code as root due to certain Polkit settings, like
allow any=yes, disabling the authentication requirement for pkexec. This can be exploited, for example, using the --gtk-module option. The affected operating systems include Ubuntu, Debian, and Gentoo.Recommendations
For USBView version 2.1, update to version 2.2 or later to resolve the issue. As a temporary workaround, consider restricting the use of
pkexec with vulnerable Polkit settings to minimize the risk of exploitation.Exploit
Fix
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Linuxmint
Ubuntu