Privilege Escalation in KTextEditor by KDE
CVE-2018-10361
7.8HIGH
What is CVE-2018-10361?
A vulnerability identified in KTextEditor versions 5.34.0 to 5.45.0 involves insecure handling of temporary files created by the kauth_ktexteditor_helper service. This flaw can be exploited by unprivileged users who can authenticate as root, allowing them to execute a symlink attack to gain unauthorized root access. The attack initiates when a user writes a text file into a directory controlled by another user, leading to potential privilege escalation and severe security risks within the local system.
