1 results (0.003 seconds)

CVSS: 8.8EPSS: 0%CPEs: 6EXPL: 1

07 Aug 2024 — An issue was discovered in Ubuntu wpa_supplicant that resulted in loading of arbitrary shared objects, which allows a local unprivileged attacker to escalate privileges to the user that wpa_supplicant runs as (usually root). Membership in the netdev group or access to the dbus interface of wpa_supplicant allow an unprivileged user to specify an arbitrary path to a module to be loaded by the wpa_supplicant process; other escalation paths might exist. Rory McNamara discovered that wpa_supplicant could be made... • https://github.com/zrax-x/CVE-2024-5290-exp • CWE-427: Uncontrolled Search Path Element •