• irmadlad@lemmy.world
    link
    fedilink
    English
    arrow-up
    7
    arrow-down
    2
    ·
    11 hours ago

    RFC: As I understand it this exploit requires local access and cannot be deployed remotely. Is this a correct analysis?

    • Eager Eagle@lemmy.worldOP
      link
      fedilink
      English
      arrow-up
      5
      ·
      5 hours ago

      right, but remote code execution comes in many different ways. Having a machine vulnerable to this kind of privilege escalation is a really bad thing.

      • irmadlad@lemmy.world
        link
        fedilink
        English
        arrow-up
        1
        ·
        4 hours ago

        Certainly. I don’t discount that any exploit is ‘really bad’. I like my OS of choice to be as free of exploits as it can possibly be. However, some of the material I was reading involved areas of Linux that I have little if any knowledge of value with, so I thought I’d as the question.

      • richmondez@lemdro.id
        link
        fedilink
        English
        arrow-up
        3
        ·
        6 hours ago

        It’s a LOCAL privilege escalation vulnerability. You need sufficient access to be able to execute arbitrary code locally on the machine. You would need a remote code execution vulnerability in an exposed service (VPN, web server, game server and so on) before an attacker could chain to this to get remote root on your system.