#VU56000 Command Injection in System Security Services Daemon (SSSD) - CVE-2021-3621
Published: August 20, 2021 / Updated: October 19, 2021
System Security Services Daemon (SSSD)
SSSD
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to improper input validation in the sssctl command within the logs-fetch and cache-expire subcommands. An attacker can trick the root user into running a specially crafted sssctl command, such as via sudo, and execute arbitrary code with root privileges.