Main
Vulnerability Database
Exploits
ID:9248 - Exploit for Untrusted search path in Python - CVE-2022-26488
ID:9248 - Exploit for Untrusted search path in Python - CVE-2022-26488
Published: August 17, 2023
Vulnerability identifier: #VU70037
Vulnerability risk: Low
CVE-ID: CVE-2022-26488
CWE-ID: CWE-426
Exploitation vector: Local access
Vulnerable software:
Python
Python
Link to public exploit:
Vulnerability description
The vulnerability allows a remote attacker to escalate privileges on the system.
The vulnerability exists due to the search path being inadequately secured. A non-administrative user can trigger a repair that incorrectly adds user-writable paths into PATH, enabling search-path hijacking of other users and system services.
Remediation
Install updates from vendor's website.