VulnerabilityModified
CVE-2019-7304
Canonical snapd before version 2.37.1 incorrectly performed socket owner validation, allowing an attacker to run arbitrary commands as root.
CRITICAL 9.8EPSS 60.8%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 60.8%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
Canonical snapd before version 2.37.1 incorrectly performed socket owner validation, allowing an attacker to run arbitrary commands as root. This issue affects: Canonical snapd versions prior to 2.37.1.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 60.81% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-863
- Affected
- canonical/snapd · canonical/ubuntu linux
- Source
- security@ubuntu.com
References
- https://usn.ubuntu.com/3887-1/Vendor Advisory
- https://www.exploit-db.com/exploits/46361Exploit, Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/46362Exploit, Third Party Advisory, VDB Entry
- https://usn.ubuntu.com/3887-1/Vendor Advisory
- https://www.exploit-db.com/exploits/46361Exploit, Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/46362Exploit, Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.