Impact
A flaw in sblim-cmpi-base permits an unprivileged local user to create a symlink in a world‑writable directory, which is then followed by privileged scripts during provider registration. This allows the attacker to redirect privileged writes to an arbitrary root‑owned file, potentially overwriting system files or disrupting services. The weakness is an insecure temporary file creation flaw classified as CWE‑377.
Affected Systems
Red Hat Enterprise Linux 10, 6, 7, 8, and 9 are affected. No specific patch version is listed; the flaw applies to all installations of sblim‑cmpi‑base on those distributions.
Risk and Exploitability
The CVSS score of 6.3 indicates medium severity. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires the registration script to run with elevated privileges and the existence of a world‑writable directory where a user can create a symlink. The likely attack vector is local, and the exploit can lead to denial of service or privilege elevation by corrupting critical system files.
OpenCVE Enrichment