Impact
The vulnerability lies in how Pardus Domain Joiner starts external processes: it passes credentials or other sensitive data as command‑line arguments or environment variables that are visible to the operating system. This visibility allows other local processes or monitoring tools to read the sensitive information, enabling credential harvesting and potential lateral movement within a domain. The weakness corresponds to CWE‑214 and has a CVSS v3.1 base score of 7.9, indicating high severity.
Affected Systems
TUBITAK BILGEM Software Technologies Research Institute’s Pardus Domain Joiner is affected. Versions 0.5.2 and 0.5.3 are vulnerable, while 0.5.4 and later versions contain the fix.
Risk and Exploitability
The EPSS score of less than 1 % indicates a very low current likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Attackers would need the ability to run or influence the domain joiner binary, normally requiring local execution or privileged access. Once executed, the process arguments or environment variables containing credentials become visible to co‑resident processes, allowing them to capture the sensitive data. If an attacker succeeds, the compromised credentials could be reused for lateral movement or unauthorized access to domain resources.
OpenCVE Enrichment