D-Bus Security Flaw in Tizen's Enlightenment System Service
CVE-2018-16266

8.1HIGH

Key Information:

Vendor
Linux
Status
Vendor
CVE Published:
22 January 2020

Summary

The Enlightenment system service in Tizen has a security vulnerability that allows an unprivileged process to gain control over or capture windows. This issue arises due to improper configurations in the D-Bus security policy and affects Tizen versions prior to 5.0 M1, including Tizen-based firmware for the Samsung Galaxy Gear series before build RE2. Exploiting this vulnerability may enable unauthorized access and system manipulation, posing significant risks to user privacy and security.

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.