peter bassill · operator
$ cve CVE-2018-15686 JSON

CVE-2018-15686 EXPLOIT

7.8
HIGH · CVSS 3.1 · EPSS 2.3% (pctl 82)

Patch early

A public exploit exists.

Description

A vulnerability in unit_deserialize of systemd allows an attacker to supply arbitrary state across systemd re-execution via NotifyAccess. This can be used to improperly influence systemd execution and possibly lead to root privilege escalation. Affected releases are systemd versions up to and including 239.

Scoring

CVSS7.8 (HIGH, v3.1)
VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS2.26% — more likely to be exploited than 82% of all CVEs
WeaknessCWE-502
On CISA KEVno
Public exploityes
Published2018-10-26
Last modified2026-06-17

Affected (4)

VendorProduct
canonicalubuntu linux
debiandebian linux
oraclecommunications cloud native core network function cloud native environment
systemd projectsystemd

Public exploits

SourceTitleDate
exploit-dbsystemd - 'reexec' State Injection2018-10-29

References

→ the Explorer  ·  watch your stack  ·  NVD