Description
A flaw was found in PolicyKit (aka polkit) 0.115 that allows a user with a uid greater than INT_MAX to successfully execute any systemctl command.
In plain language
AI Worth attentionCVE-2018-19788 is a Polkit/PolicyKit bug in version 0.115 that could let an attacker run any `systemctl` command if they can use an account with an extremely large user ID; most small businesses won’t be affected, but if your Debian/Ubuntu servers use Polkit 0.115 you should upgrade.
In PolicyKit (polkit) 0.115, a flaw (CWE-20) allows a user with a UID greater than INT_MAX to execute any `systemctl` command, with network reachability and no user interaction under the default configuration.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:LPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2018-19788 and every CVE in our database. Create a free account — no credit card required.
Create Free Account