systemd-homed: local privilege escalation via missing home-record signature verification on the authenticate path
10Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 6.7
exploitation probability
—
observed exploitation
nono source reports it
systemd-homed contains a local privilege escalation bug via arbitrary system group addition to a local, logged in, homed-managed user
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
Affected products
systemd · systemd-homed