ID:9248 - Exploit for Untrusted search path in Python - CVE-2022-26488

 
Main Vulnerability Database Exploits ID:9248 - Exploit for Untrusted search path in Python - CVE-2022-26488

ID:9248 - Exploit for Untrusted search path in Python - CVE-2022-26488

Published: August 17, 2023


Vulnerability identifier: #VU70037
Vulnerability risk: Low
CVE-ID: CVE-2022-26488
CWE-ID: CWE-426
Exploitation vector: Local access
Vulnerable software:
Python

Link to public exploit:


Vulnerability description

The vulnerability allows a remote attacker to escalate privileges on the system.

The vulnerability exists due to the search path being inadequately secured. A non-administrative user can trigger a repair that incorrectly adds user-writable paths into PATH, enabling search-path hijacking of other users and system services.


Remediation

Install updates from vendor's website.