Command Injection in Enlightenment - CVE-2022-37706
Published: September 23, 2022 / Updated: October 25, 2024
Vulnerability identifier: #VU67606
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-37706
CWE-ID: CWE-77
Exploitation vector: Local access
Exploit availability:
Public exploit is available
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to improper input validation in the window manager. A local unprivileged user can inject and execute arbitrary OS commands with root privileges.
Affected software
Enlightenment
Debian Linux
Fedora
e17 (Debian package)
enlightenment
efl
Debian Linux
Fedora
e17 (Debian package)
enlightenment
efl
How to mitigate CVE-2022-37706
Install updates from vendor's website.
Enlightenment - update to 0.25.4
e17 (Debian package) - update to 0.24.2-8+deb11u1
enlightenment - addressed in versions 0.25.4-1.fc35, 0.25.4-1.fc36, 0.25.4-1.fc37
efl - addressed in versions 1.26.3-1.fc35, 1.26.3-1.fc36, 1.26.3-1.fc37
e17 (Debian package) - update to 0.24.2-8+deb11u1
enlightenment - addressed in versions 0.25.4-1.fc35, 0.25.4-1.fc36, 0.25.4-1.fc37
efl - addressed in versions 1.26.3-1.fc35, 1.26.3-1.fc36, 1.26.3-1.fc37
Links to Public Exploits and PoC-codes
- Exploit #10745 - Enlightenment v0.25.3 - Privilege escalation (October 25, 2024)
- Exploit #10187 - CVE-2022-37706 (The exploit is tested on Ubuntu 22.04) (July 5, 2024)
- Exploit #9947 - CVE-2022-37706 (Exploit created by nu11secur1ty (https://github.com/nu11secur1ty/CVE-mitre/tree/main/CVE-2022-37706)) (June 7, 2024)
- Exploit #9004 - CVE-2022-37706-LPE-exploit () (April 26, 2023)
- Exploit #8437 - Ubuntu Enlightenment Mount Priv Esc (October 4, 2022)
- Exploit #8392 - CVE-2022-37706-LPE-exploit (A reliable exploit + write-up to elevate privileges to root. (Tested on Ubuntu 22.04)) (September 23, 2022)
- Exploit #8391 - CVE-2022-37706 (All Credit to MaherAzzouzi (https://github.com/MaherAzzouzi/CVE-2022-37706-LPE-exploit). This is a copy of the exploit for CTFs) (September 23, 2022)