cbcvebase.
CVE-2019-3843
published 2019-04-26

CVE-2019-3843: It was discovered that a systemd service that uses DynamicUser property can create a SUID/SGID binary that would be allowed to run as the transient service…

PriorityP341high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EXPLOIT
EPSS
0.91%
56.0th percentile
It was discovered that a systemd service that uses DynamicUser property can create a SUID/SGID binary that would be allowed to run as the transient service UID/GID even after the service is terminated. A local attacker may use this flaw to access resources that will be owned by a potentially different service in the future, when the UID/GID will be recycled.

Affected

15 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiansystemd< systemd 242-4 (bookworm)systemd 242-4 (bookworm)
fedoraprojectfedora
msrccbl_mariner_1.0_arm
msrccbl_mariner_1.0_x64
msrccm1_systemd_239-34_on_cbl_mariner_1.0
systemd_projectsystemd< 242242
systemd_projectsystemd>= 0 < 242-4242-4
systemd_projectsystemd>= 0 < 242-4242-4
systemd_projectsystemd>= 0 < 242-4242-4
systemd_projectsystemd>= 0 < 242-4242-4
systemd_projectsystemd>= 0 < 229-4ubuntu21.27229-4ubuntu21.27
systemd_projectsystemd>= 0 < 237-3ubuntu10.38237-3ubuntu10.38

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv3.04.5MEDIUMCVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv7.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu4.7MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.