A logged in user may elevate its permissions by abusing a Time-of-Check to Time-of-Use (TOCTOU) race condition. When a particular process flow is initiated, an attacker can exploit this condition to gain unauthorized elevated privileges on the affected system.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 07 Mar 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published:

Updated: 2025-03-07T18:23:51.147Z

Reserved: 2023-07-12T01:00:11.881Z

Link: CVE-2023-38041

cve-icon Vulnrichment

Updated: 2024-08-02T17:30:13.558Z

cve-icon NVD

Status : Modified

Published: 2023-10-25T18:17:28.757

Modified: 2025-03-07T19:15:35.757

Link: CVE-2023-38041

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.