← volver
CVE-2024-48990highCWE-427

CVE-2024-48990

41Vexday Risk Score

Corrige pronto. Ella tiene exploit funcional público.

ssvc Attendcvss 7.8epss 20%
de la publicación al arma0 días
Publicada en NVD19 nov
metasploit19 nov
probabilidad de explotación
20%top 3% de las CVE
explotación observada
noninguna fuente lo reporta
Qualys discovered that needrestart, before version 3.8, allows local attackers to execute arbitrary code as root by tricking needrestart into running the Python interpreter with an attacker-controlled PYTHONPATH environment variable.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Productos afectados
needrestart · needrestart