Improper privilege management in Sudo - CVE-2023-7090

 

Improper privilege management in Sudo - CVE-2023-7090

Published: January 24, 2024


Vulnerability identifier: #VU85765
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-7090
CWE-ID: CWE-269
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges.

The vulnerability exists due to improper privilege management when handling ipa_hostname, where ipa_hostname from /etc/sssd/sssd.conf was not propagated in sudo. A local user can escalate privileges in applications, where client hosts retain privileges even after retracting them.


Affected software

Sudo
Dell EMC PowerProtect Data Protection
SmartFabric OS10
Enterprise SONiC
RecoverPoint for Virtual Machines

How to mitigate CVE-2023-7090

Install updates from vendor's website.

Sudo - update to 1.8.28p1
Dell EMC PowerProtect Data Protection - update to 2.7.8
RecoverPoint for Virtual Machines - update to 6.0 SP2 P1
SmartFabric OS10 - addressed in versions 10.5.5.9, 10.5.6.1
Enterprise SONiC - update to 4.2.1

External References

Related Security Bulletins