超危
Sudo --chroot参数特权提升漏洞
2025-06-30 00:00:00 公开 ,2026-03-04 03:33:56 更新
- CISA KEV
- 关键漏洞
- 本地
- 无需认证
- 开源组件漏洞
- 公开PoC
- CWEs:
- CWE-829 (Inclusion of Functionality from Untrusted Control Sphere)
- CAPEC:
- CAPEC-175 (Code Inclusion) 、 CAPEC-201 (Serialized Data External Linking) 、 CAPEC-228 (DTD Injection) 、 CAPEC-251 (Local Code Inclusion) 、 CAPEC-252 (PHP Local File Inclusion) 、 CAPEC-253 (Remote Code Inclusion) 、 CAPEC-263 (Force Use of Corrupted Files) 、 CAPEC-538 (Open-Source Library Manipulation) 、 CAPEC-549 (Local Execution of Code) 、 CAPEC-640 (Inclusion of Code in Existing Process) 、 CAPEC-660 (Root/Jailbreak Detection Evasion via Hooking) 、 CAPEC-695 (Repo Jacking) 、 CAPEC-698 (Install Malicious Extension)
- SSVC:
- 可利用状态:已被积极利用攻击自动化:否技术影响评估:全部 2025-09-27 11:55:22