#VU18435 Permissions, Privileges, and Access Controls in systemd - CVE-2019-3843
Published: May 13, 2019 / Updated: January 29, 2020
systemd
Freedesktop.org
Description
The vulnerability allows a remote attacker to escalate privileges on the system.
The vulnerability exists due to an error in the process of binary creation, when the DynamicUser property is used to create a SUID or SGID binary for a systemd service. A local user can abuse the systemd functionality to execute arbitrary code on the target system with elevated privileges.