Privilege Escalation in Dbus-glib Affects Local Users
CVE-2013-0292

Currently unrated

Key Information:

Status
Vendor
CVE Published:
5 March 2013

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2013-0292?

The dbus_g_proxy_manager_filter function in Dbus-glib versions prior to 0.100.1 lacks proper validation of the sender for NameOwnerChanged signals. This oversight enables local users to exploit the vulnerability by sending spoofed signals, potentially allowing them to elevate their privileges and perform unauthorized actions in the system.

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.