Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:24164
HistoryApr 10, 2020 - 12:47 a.m.

Privilege Escalation

2020-04-1000:47:56
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
2

0.0004 Low

EPSS

Percentile

10.3%

The sudo (superuser do) utility is vulnerable to Privilege Escalation. A flaw was found in the way sudo handled Runas specifications containing both a user and a group list. If a local user were authorized by the sudoers file to perform their sudo commands with the privileges of a specified user and group, they could use this flaw to run those commands with the privileges of either an arbitrary user or group on the system.

References