Untrusted search path in Wake Up Latency Tracer (WULT) - CVE-2023-27298

 

Untrusted search path in Wake Up Latency Tracer (WULT) - CVE-2023-27298

Published: May 11, 2023


Vulnerability identifier: #VU76026
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-27298
CWE-ID: CWE-426
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to escalate privileges on the system.

The vulnerability exists due to uncontrolled search path, which leads to security restrictions bypass and privilege escalation.


Affected software

Wake Up Latency Tracer (WULT)

How to mitigate CVE-2023-27298

Install updates from vendor's website.

Wake Up Latency Tracer (WULT) - update to 1.0.0 commit id 592300b

External References

Related Security Bulletins