CVE-2019-3843 is a local privilege escalation vulnerability affecting systemd, specifically impacting Canonical, FedoraProject, and NetApp products. It allows a local attacker to create SUID/SGID binaries through a systemd service utilizing the DynamicUser property. This enables access to resources that may be owned by a different service in the future when the transient UID/GID is recycled. Rated 7.8 HIGH on the CVSS scale, this vulnerability has a low attack complexity and requires local user privileges, but can lead to high impact on confidentiality, integrity, and availability. The FAUCET Risk Score is 89/100, indicating significant risk. While not listed on the CISA KEV catalog or Hot List, and with no evidence of active exploitation, an ExploitDB proof-of-concept (EDB-46760) exists. There is minimal community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 242CPE matchmatch criteria | cpe:2.3:a:systemd_project:systemd:*:*:*:*:*:*:*:* | ||
30CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:* | ||
16.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:* | ||
18.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:* | ||
19.10CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:19.10:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2019-3843
Aug 11, 2020systemd: services with DynamicUser can create SUID/SGID binaries
Apr 25, 2019It was discovered that a systemd service that uses DynamicUser property can create a SUID/SGID binary that would be allowed to run as the transient service UID/GID even after the service is terminated. A local attacker may use this flaw to access resources that will be owned by a potentially different service in the future when the UID/GID will be recycled.
Apr 9, 2019