cbcvebase.
CVE-2018-15687
published 2018-10-26

CVE-2018-15687: A race condition in chown_one() of systemd allows an attacker to cause systemd to set arbitrary permissions on arbitrary files. Affected releases are systemd…

PriorityP338high7CVSS 3.1
AVLACHPRLUINSUCHIHAH
EXPLOIT
EPSS
1.06%
60.5th percentile
A race condition in chown_one() of systemd allows an attacker to cause systemd to set arbitrary permissions on arbitrary files. Affected releases are systemd versions up to and including 239.

Affected

18 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiansystemd< systemd 239-11 (bookworm)systemd 239-11 (bookworm)
msrccbl_mariner_1.0_arm
msrccbl_mariner_1.0_x64
msrccm1_systemd_239-31_on_cbl_mariner_1.0
systemdsystemdunspecified – 239
systemd_projectsystemd>= 0 < 239-11239-11
systemd_projectsystemd>= 0 < 239-11239-11
systemd_projectsystemd>= 0 < 239-11239-11
systemd_projectsystemd>= 0 < 239-11239-11
systemd_projectsystemd>= 0 < 229-4ubuntu21.9229-4ubuntu21.9
systemd_projectsystemd>= 0 < 229-4ubuntu21.10229-4ubuntu21.10
systemd_projectsystemd>= 0 < 229-4ubuntu21.8229-4ubuntu21.8
systemd_projectsystemd>= 0 < 237-3ubuntu10.9237-3ubuntu10.9
systemd_projectsystemd>= 0 < 237-3ubuntu10.6237-3ubuntu10.6
systemd_projectsystemd>= 235 < 240240

CVSS provenance

nvdv3.17.0HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian7.0HIGH
vendor_msrc7.0HIGH
vendor_redhat7.0HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.