Impact
The vulnerability allows unprivileged software running on a system where a privileged user exists to achieve privilege escalation through an uncontrolled search path. This flaw can compromise confidentiality, integrity, and availability of the affected system. The described attack requires low complexity conditions and may proceed with passive user interaction, but no special internal knowledge is needed. The impact is severe, providing the attacker full control over the system, thereby threatening all three security objectives.
Affected Systems
Approximate Bayesian Inference Framework versions prior to the repository commit identified as 484c949. No specific product or vendor versions are listed in the CVE data, so any build of the framework before this commit is considered vulnerable.
Risk and Exploitability
The CVSS score of 5.4 indicates a moderate severity overall, while the EPSS score of less than 1% suggests a very low probability of exploitation in the wild. The flaw is not currently listed in the CISA Known Exploited Vulnerabilities catalog. The attack is likely delivered locally, requiring a privileged user account and minimal attack complexity. Because the exploit path relies on local conditions, the risk to remote systems without access is limited, but systems where both privileged and unprivileged users coexist are at higher risk.
OpenCVE Enrichment