CVE Vulnerabilities

CVE-2017-2663

Privilege Context Switching Error

Published: Jul 27, 2018 | Modified: Nov 21, 2024
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
4.6 MEDIUM
AV:L/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

It was found that subscription-managers DBus interface before 1.19.4 let unprivileged user access the com.redhat.RHSM1.Facts.GetFacts and com.redhat.RHSM1.Config.Set methods. An unprivileged local attacker could use these methods to gain access to private information, or launch a privilege escalation attack.

Weakness

The product does not properly manage privileges while it is switching between different contexts that have different privileges or spheres of control.

Affected Software

Name Vendor Start Version End Version
Subscription-manager Redhat * 1.19.4 (excluding)

Potential Mitigations

References