QID 198645

Date Published: 2022-01-27

QID 198645: Ubuntu Security Notification for PolicyKit Vulnerability (USN-5252-1) (PwnKit)

The policykit pkexec tool incorrectly handledcommand-line arguments.

A local attacker could use this issue to escalateprivileges to an administrator.

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as High - 7.2 severity.
  • Solution
    Refer to Ubuntu security advisory USN-5252-1 for updates and patch information.
    Vendor References

    CVEs related to QID 198645

    Software Advisories
    Advisory ID Software Component Link
    USN-5252-1 Ubuntu Linux URL Logo ubuntu.com/security/notices/USN-5252-1