Privilege Escalation Vulnerability in pppd Passprompt Plugin by ppp Project
CVE-2024-58250

9.3CRITICAL

Key Information:

Vendor

Samba

Status
Vendor
CVE Published:
22 April 2025

What is CVE-2024-58250?

The passprompt plugin in pppd prior to version 2.5.2 has a vulnerability that could lead to improper handling of privileges. This misconfiguration may allow an attacker to escalate their privileges, potentially leading to unauthorized access and control over the affected system. Users of pppd are advised to update their installations to the latest version to mitigate the risks associated with this vulnerability.

Affected Version(s)

ppp 0 < 2.5.2

References

CVSS V3.1

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2024-58250 : Privilege Escalation Vulnerability in pppd Passprompt Plugin by ppp Project