Robotmk before 2.0.1 allows a local user to escalate privileges (e.g., to SYSTEM) if automated Python environment setup is enabled, because the "shared holotree usage" feature allows any user to edit any Python environment.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-38308 | Robotmk before 2.0.1 allows a local user to escalate privileges (e.g., to SYSTEM) if automated Python environment setup is enabled, because the "shared holotree usage" feature allows any user to edit any Python environment. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-02T04:33:11.627Z
Reserved: 2024-07-04T00:00:00
Link: CVE-2024-39934
Updated: 2024-08-02T04:33:11.627Z
Status : Awaiting Analysis
Published: 2024-07-04T19:15:10.967
Modified: 2024-11-21T09:28:36.553
Link: CVE-2024-39934
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD