EXPOSURES › CVE-2023-0386
CVE-2023-0386
HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
⚡ RCE
⌖ EXPLOITED IN THE WILD
SHAME 72/100
exploited-in-wildunpatchedrce
Linux Kernel escalation flaw exploited
A local user exploited an unpatched Linux Kernel vulnerability in OverlayFS, allowing privilege escalation on the system.
Shame score — Unpatched vulnerability enabling local escalation of privileges.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
PLAYERS IMPLICATED
DESCRIPTION
Linux Kernel contains an improper ownership management vulnerability, where unauthorized access to the execution of the setuid file with capabilities was found in the Linux kernel’s OverlayFS subsystem in how a user copies a capable file from a nosuid mount into another mount. This uid mapping bug allows a local user to escalate their privileges on the system.
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.