CVE-2020-8933 is a privilege escalation vulnerability in Google Cloud Platform's guest-oslogin, affecting versions between 20190304 and 20200507, as well as OpenSUSE guest-oslogin and leap. An attacker with only the "roles/compute.osLogin" role can leverage membership in the "lxd" group to attach host devices and filesystems. This allows modification of the host OS filesystem, specifically /etc/sudoers, to gain root privileges. Rated with a CVSS score of 7.8 (HIGH), this vulnerability has a low attack complexity and requires local access, but can lead to complete compromise of confidentiality, integrity, and availability. While the EPSS score is low, indicating a low probability of exploitation in the wild, the FAUCET Risk Score is 57/100. There is no evidence of active exploitation, and no public exploit code is available on platforms like Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, suggesting a lack of widespread attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 20190304.00, <= 20200507.00CPE matchmatch criteria | cpe:2.3:a:google:guest-oslogin:*:*:*:*:*:*:*:* | ||
15.1CPE matchmatch criteria | cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:* | ||
15.2CPE matchmatch criteria | cpe:2.3:o:opensuse:leap:15.2:*:*:*:*:*:*:* | ||
>= 20190304, < 20200507CPE match | cpe:2.3:a:google:guest-oslogin:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Compute Engine OS Login Privilege Escalation Vulnerabilities
Jun 19, 2020Compute Engine OS Login Privilege Escalation
Jun 19, 2020VMs that have OS Login enabled might be susceptible to privilege escalation vulnerabilities. These vulnerabilities gives users that are granted OS Login permissions (but not given admin access) the ability to escalate to root access in the VM.