PT-2022-17918 · Unknown+1 · Miniconda3+1
Published
2022-03-17
·
Updated
2024-03-06
·
CVE-2022-26526
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Anaconda3 versions through 2021.11.0.0
Miniconda3 versions through 4.11.0.0
Description
The issue allows local users to gain privileges by placing a Trojan horse file into a world-writable directory under %PROGRAMDATA% that is added to the system PATH environment variable. This problem can only occur in non-default installations where the product is installed for all users and the system PATH is changed.
Recommendations
For Anaconda3 versions through 2021.11.0.0, avoid installing the product for all users or modifying the system PATH to prevent exploitation.
For Miniconda3 versions through 4.11.0.0, consider restricting access to the world-writable directory under %PROGRAMDATA% until a fix is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
LPE
Incorrect Permission
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Anaconda3
Miniconda3