vendor:
Enlightenment
by:
nu11secur1ty
7.8
CVSS
HIGH
Privilege escalation
264
CWE
Product Name: Enlightenment
Affected Version From: 0.25.3
Affected Version To: 0.25.3
Patch Exists: YES
Related CWE: CVE-2022-37706
CPE: a:enlightenment:enlightenment:0.25.3
Platforms Tested: Ubuntu 22.10
2022
Exploit Title: Enlightenment v0.25.3 – Privilege escalation
The Enlightenment Version: 0.25.3 is vulnerable to local privilege escalation. Enlightenment_sys in Enlightenment before 0.25.3 allows local users to gain privileges because it is setuid root, and the system library function mishandles pathnames that begin with a /dev/.. substring. If the attacker has access locally to some machine on which the machine is installed Enlightenment he can use this vulnerability to do very dangerous stuff.
Mitigation:
Ensure that the Enlightenment_sys binary is not setuid root and that pathnames beginning with a /dev/.. substring are properly handled.