vendor:
diag
by:
Unknown
7.5
CVSS
HIGH
Local Privilege Escalation
269
CWE
Product Name: diag
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: NO
Related CWE:
CPE: a:diag
Platforms Tested:
Unknown
Local Privilege Escalation in diag
The vulnerability exists in diag applications due to a failure to implement security controls properly when executing an application specified by the 'DIAGNOSTICS' environment variable. A local attacker can exploit this vulnerability to gain superuser privileges on a computer running the affected software. The attacker can create a directory and set the 'DIAGNOSTICS' environment variable to that directory. Then, by executing a specially crafted script, the attacker can escalate their privileges and gain superuser access.
Mitigation:
It is recommended to apply the latest patches or updates from the vendor to fix this vulnerability. Additionally, restricting access to the 'DIAGNOSTICS' environment variable and ensuring proper input validation can help mitigate the risk.