PT-2026-24809 · Microsoft+1 · Intune+2
Khronosd
·
Published
2026-03-11
·
Updated
2026-04-15
·
CVE-2026-31979
CVSS v3.1
8.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Himmelblau versions prior to 3.1.0
Himmelblau versions prior to 2.3.8
Description
Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. The
himmelblaud-tasks daemon, running as root, writes Kerberos cache files under /tmp/krb5cc <uid> without symlink protections. The PrivateTmp setting was removed from the daemon’s systemd hardening, exposing it to the host /tmp. A local user can exploit this through symlink attacks to overwrite arbitrary files, potentially achieving local privilege escalation. This is a Time-of-Check to Time-of-Use (TOCTOU) vulnerability where a Kerberos cache file can be swapped for a symlink to /etc/shadow, allowing an unprivileged user to gain control of system credentials.Recommendations
Versions prior to 3.1.0: Update to version 3.1.0.
Versions prior to 2.3.8: Update to version 2.3.8.
Exploit
Fix
LPE
Link Following
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Himmelblau
Intune
Azure Entra Id