vulnerability

FreeBSD: VID-0baee383-356c-11e7-b9a9-50e549ebab6c (CVE-2017-8422): kauth: Local privilege escalation

Severity
7
CVSS
(AV:L/AC:L/Au:N/C:C/I:C/A:C)
Published
May 10, 2017
Added
May 10, 2017
Modified
Dec 10, 2025

Description

Albert Astals Cid reports: KAuth contains a logic flaw in which the service invoking dbus is not properly checked. This allows spoofing the identity of the caller and with some carefully crafted calls can lead to gaining root from an unprivileged account.

Solutions

freebsd-upgrade-package-kdelibsfreebsd-upgrade-package-kf5-kauth
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.