Microsoft warns: These flaws could give attackers root privileges on Linux desktops

Microsoft has discovered vulnerabilities in system components commonly used on Linux desktops that could allow an attacker to elevate privileges to root and install malware. 

Gaining root privileges on a compromised Linux desktop would allow the attackers to perform nefarious tasks, such as installing a root backdoor, or to undertake other malicious actions via arbitrary root code execution via the flaws Microsoft is calling Nimbuspwn.

“Moreover, the Nimbuspwn vulnerabilities could potentially be leveraged as a vector for root access by more sophisticated threats, such as malware or ransomware, to achieve greater impact on vulnerable devices,” Microsoft said.

The two bugs, tracked as CVE-2022-29799 and CVE-2022-29800, were found in networkd-dispatcher, a dispatcher service for systemd-networkd network connection status changes. Microsoft said it discovered the vulnerabilities by listening to messages on the System Bus while performing code reviews and dynamic analysis on services that run as root – and spotting an odd pattern in networkd-dispatcher. 

SEE: These are the problems that cause headaches for bug bounty hunters

D-Bus is developed by the freedesktop.org project, while networkd-dispatcher is maintained by Clayton Craft, who has updated his component to address the flaws Microsoft found.

D-Bus components are a nice target for attackers. First, many D-Bus components ship by default on popular desktop Linux distributions, such as Linux Mint. Second, the components run at different privileges and respond to messages. For example, a video-conferencing app sending a D-Bus signal indicating that a call has started could tell any apps listening to respond by muting their audio.  

But D-Bus leads to an even better target: System Bus, which led Jonathan Bar Or, of the Microsoft 365 Defender Research Team, to the discovery of issues in networkd-dispatcher.  

“D-Bus exposes a global System Bus and a per-session Session Bus. From an attacker’s perspective, the System Bus is more attractive since it will commonly have services that run as root listening to it,” explains Or in a blogpost

The security issues in networkd-dispatcher included a directory traversal, symlink race, and time-of-check-time-of-use race condition issues, which could be combined by an attacker to elevate privileges to root and from there install malware.

Given Craft has updated networkd-dispatcher and exploit examples are public, Linux desktop users should update the affected component as soon as possible.

“We wish to thank Clayton for his professionalism and collaboration in resolving those issues. Users of networkd-dispatcher are encouraged to update their instances,” Microsoft said.

Note: This article have been indexed to our site. We do not claim legitimacy, ownership or copyright of any of the content above. To see the article at original source Click Here

Related Posts
Quel smartphone Huawei choisir en 2022 ? thumbnail

Quel smartphone Huawei choisir en 2022 ?

En dépit des déboires de Huawei avec les USA, certains modèles de smartphones de la marque restent intéressants. Voici nos recommandations pour trouver le meilleur téléphone Huawei. Les meilleurs smartphones Huawei Le haut de gamme 7 /10 Un excellent écran AMOLED de 6,58 pouces Un module photo de très grande qualité ... mais sans les…
Read More
AMD collaborates with TSMC for Zen 5 chips thumbnail

AMD collaborates with TSMC for Zen 5 chips

AMD plans to mass-produce its Zen 5 chips in the third quarter of 2024, continuing its collaboration with TSMC, according to Taiwanese media outlet United Daily News. AMD collaborates with TSMC to outsource the production of the Zen 5 chips, as the US chip company aims to enhance its presence in AI terminals and expand
Read More
Apple Health app now supports vaccination QR codes from several provinces thumbnail

Apple Health app now supports vaccination QR codes from several provinces

The app reportedly supports adding vaccination QR codes from Alberta, B.C. and Saskatchewan With the release of iOS 15.0.1, Albertans can reportedly add their COVID-19 vaccination QR codes to the Apple Health app on their iPhones. According iPhone in Canada, Alberta’s vaccination QR codes support the ‘SMART Health Card’ spec, which is why they work…
Read More
Colin Trevorrow's Next Movie Will Go Underwater to Atlantis thumbnail

Colin Trevorrow’s Next Movie Will Go Underwater to Atlantis

Image: CHRIS PIZZELLO/INVISION/APFor his next film, director Colin Trevorrow is going under the sea.Per the Hollywood Reporter, the director of Jurassic World and near-director on Star Wars Episode IX will be directing and producing Atlantis for Skydance. The filmmaker will be working from a script written by Charmaine DeGraté, an executive producer on HBO’s House
Read More
Index Of News
Total
0
Share