GHSA-vr7j-w64f-pgvwHigh
DigitalCanion has discovered a vulnerability that allows an attacker to cause the system to load...
🔗 CVE IDs covered (1)
📋 Description
DigitalCanion has discovered a vulnerability that allows an attacker to cause the system to load an attacker-controlled .so file instead of the expected legitimate module. The loading mechanism relies on a predictable module name without adequately verifying the file’s origin or integrity. A malicious shared object using the expected name can therefore be loaded by a privileged process. The module code then executes within the context and privileges of that process. This results in arbitrary code execution and full compromise of the Mitel Linux virtual machine.