CVE-2024-48990 is a high-severity privilege escalation vulnerability affecting needrestart versions prior to 3.8, allowing local attackers to execute arbitrary code as root. This is achieved by manipulating the PYTHONPATH environment variable, tricking needrestart into running the Python interpreter with attacker-controlled input. With a CVSS score of 7.8, the vulnerability has a low attack complexity and can lead to complete compromise of confidentiality, integrity, and availability. While not yet listed in CISA KEV, a Metasploit module exists, and the vulnerability has garnered significant community discussion and media coverage, indicating a high potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.8CPE matchmatch criteria | cpe:2.3:a:needrestart_project:needrestart:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.