vulnerability
FreeBSD: VID-0baee383-356c-11e7-b9a9-50e549ebab6c (CVE-2017-8422): kauth: Local privilege escalation
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 7 | (AV:L/AC:L/Au:N/C:C/I:C/A:C) | May 10, 2017 | May 10, 2017 | Dec 10, 2025 |
Severity
7
CVSS
(AV:L/AC:L/Au:N/C:C/I:C/A:C)
Published
May 10, 2017
Added
May 10, 2017
Modified
Dec 10, 2025
Description
Albert Astals Cid reports: KAuth contains a logic flaw in which the service invoking dbus is not properly checked. This allows spoofing the identity of the caller and with some carefully crafted calls can lead to gaining root from an unprivileged account.
Solutions
freebsd-upgrade-package-kdelibsfreebsd-upgrade-package-kf5-kauth
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.