Local Privilege Escalation in Icinga 2 by Icinga Software
CVE-2017-16933
7HIGH
What is CVE-2017-16933?
The chown call in the etc/initsystem/prepare-dirs script of Icinga 2 versions up to 2.8.1 creates a security risk by allowing local users to exploit the $ICINGA2_USER account. This vulnerability can be leveraged to escalate privileges due to improper handling of filenames in user-writable directories, enabling unauthorized users to create symbolic links that lead to increased access.
