Aller au contenu

Fiche vulnérabilité

CVE-2023-1277 : faille élevée ubuntukylin kylin-system-updater (CVSS 7.8)

Description

A vulnerability, which was classified as critical, was found in kylin-system-updater up to 1.4.20kord on Ubuntu Kylin. Affected is the function InstallSnap of the component Update Handler. The manipulation leads to command injection. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-222600.

En bref

Sévérité
Élevée (CVSS 7.8)
Vecteur CVSS
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
8 mars 2023
Dernière mise à jour
17 juin 2026

Produits concernés

  • ubuntukylin kylin-system-updater

Références

Rechercher une autre vulnérabilité dans la base CVE