Impact
The issue appears in uutils coreutils versions earlier than 0.10.0. During installation the routine sets the setuid or setgid bit on destination files before attempting to modify ownership. When the ownership change fails, the setuid bit remains, leaving a privileged executable owned by the original invoker. An attacker who can induce such a failure may run the leftover binary with elevated privileges, effectively gaining higher rights than intended.
Affected Systems
This flaw affects the uutils coreutils package. It applies to any installation performed with 'install' from a pre‑0.10.0 release. The impact is specific to systems where the install command is run by a user who has write permissions to target directories and can trigger ownership‑change failures on capability‑restricted setups.
Risk and Exploitability
The CVSS score of 7.3 indicates a serious security risk. The EPSS score is < 1%, suggesting a very low but non‑zero probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires local access: the attacker must invoke the install routine, cause an ownership‑change failure, and then execute the lingering setuid binary. Successful exploitation results in full privilege escalation on the affected system.
OpenCVE Enrichment