CVE-2022-26526
Anaconda Anaconda3 (Anaconda Distribution) through 2021.11.0.0 and Miniconda3 through 4.11.0.0 can create a world-writable directory under %PROGRAMDATA% and place that directory into the system PATH environment variable.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.33%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Anaconda Anaconda3 (Anaconda Distribution) through 2021.11.0.0 and Miniconda3 through 4.11.0.0 can create a world-writable directory under %PROGRAMDATA% and place that directory into the system PATH environment variable. Thus, for example, local users can gain privileges by placing a Trojan horse file into that directory. (This problem can only happen in a non-default installation. The person who installs the product must specify that it is being installed for all users. Also, the person who installs the product must specify that the system PATH should be changed.
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.33% probability · 26th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-732
- Affected
- anaconda/anaconda3 · conda/miniconda3
- Source
- cve@mitre.org
References
- https://docs.conda.io/en/latest/miniconda.htmlProduct, Vendor Advisory
- https://github.com/continuumio/anaconda-issues/issuesIssue Tracking, Third Party Advisory
- https://improsec.com/tech-blog/privilege-escalation-vulnerability-in-anaconda3-and-miniconda3Exploit, Third Party Advisory
- https://repo.anaconda.com/miniconda/Vendor Advisory
- https://docs.conda.io/en/latest/miniconda.htmlProduct, Vendor Advisory
- https://github.com/continuumio/anaconda-issues/issuesIssue Tracking, Third Party Advisory
- https://improsec.com/tech-blog/privilege-escalation-vulnerability-in-anaconda3-and-miniconda3Exploit, Third Party Advisory
- https://repo.anaconda.com/miniconda/Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.