Uncontrolled Search Path Element
CVE-2024-5290
Summary
An issue was discovered in Ubuntu's "wpa_supplicant" that allows the loading of arbitrary shared objects. This vulnerability enables a local, unprivileged attacker to escalate privileges to the user that "wpa_supplicant" runs as, typically root. Membership in the "netdev" group or access to the D-Bus interface of "wpa_supplicant" allows an unprivileged user to specify an arbitrary path to a module to be loaded by the "wpa_supplicant" process. Other escalation paths may also exist.
- LOW
- LOCAL
- HIGH
- UNCHANGED
- NONE
- LOW
- HIGH
- HIGH
CWE-427 - Uncontrolled Search Path Element
The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.
Advisory Timeline
- Published