← Πίσω στην αναζήτηση CVE

CVE-2026-34397

Himmelblau

Περιγραφή

Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. From versions 2.0.0-alpha to before 2.3.9 and 3.0.0-alpha to before 3.1.1, there is a conditional local privilege escalation vulnerability in an edge-case naming collision. Only authenticated himmelblau users whose mapped CN/short name exactly matches a privileged local group name (e.g., -sudo-, -wheel-, -docker-, -adm-) can cause the NSS module to resolve that group name to their fake primary group. If the system uses NSS results for group-based authorization decisions (sudo, polkit, etc.), this can grant the attacker the privileges of that group. This issue has been patched in versions 2.3.9 and 3.1.1.

CVSS 6.3EPSS 0.158%Κίνδυνος 0.64
Προβολή πηγής
Δημοσίευση
2026-04-01 18:16:30
Επηρεαζόμενες εκδόσεις
>=2.0.0-alpha, <2.3.9, >=3.0.0-alpha, <3.1.1
Τύπος
Core software
Διάνυσμα
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N