Lucene search

K
redhatcveRedhat.comRH:CVE-2020-14342
HistorySep 07, 2020 - 7:19 a.m.

CVE-2020-14342

2020-09-0707:19:40
redhat.com
access.redhat.com
13

0.002 Low

EPSS

Percentile

52.4%

A flaw was found in cifs-utils’ mount.cifs where it was invoking a shell when requesting the Samba password, which could be used to inject arbitrary commands. This flaw allows an attacker who can invoke mount.cifs with special permission, such as via sudo rules, to escalate their privileges. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.