A flaw was found in the grub2-set-bootflag utility of grub2. A local attacker could run this utility under resource pressure (for example b…
A flaw was found in the grub2-set-bootflag utility of grub2. A local attacker could run this utility under resource pressure (for example by setting RLIMIT), causing grub2 configuration files to be truncated and leaving the system unbootable on subsequent reboots.
A particular privilege, role, capability, or right can be used to perform unsafe actions that were not intended, even when it is assigned to the correct entity.
https://cwe.mitre.org/data/definitions/267.html →Open in CWE collection →An adversary identifies a Rest HTTP (Get, Put, Delete) style permission method allowing them to perform various malicious actions upon server data due to lack of access control mechanisms implemented within the application service accepting HTTP messages.
https://capec.mitre.org/data/definitions/58.html →Open in CAPEC collection →The adversary exploits the target system's audio and video functionalities through malware or scheduled tasks. The goal is to capture sensitive information about the target for financial, personal, political, or other gains which is accomplished by collecting communication data between two parties via the use of peripheral devices (e.g. microphones and webcams) or applications with audio and video capabilities (e.g. Skype) on a system.
https://capec.mitre.org/data/definitions/634.html →Open in CAPEC collection →The adversary exploits an application that allows for the copying of sensitive data or information by collecting information copied to the clipboard. Data copied to the clipboard can be accessed by other applications, such as malware built to exfiltrate or log clipboard contents on a periodic basis. In this way, the adversary aims to garner information to which they are unauthorized.
https://capec.mitre.org/data/definitions/637.html →Open in CAPEC collection →An adversary discovers connections between systems by exploiting the target system's standard practice of revealing them in searchable, common areas. Through the identification of shared folders/drives between systems, the adversary may further their goals of locating and collecting sensitive information/files, or map potential routes for lateral movement within the network.
https://capec.mitre.org/data/definitions/643.html →Open in CAPEC collection →An adversary gathers sensitive information by exploiting the system's screen capture functionality. Through screenshots, the adversary aims to see what happens on the screen over the course of an operation. The adversary can leverage information gathered in order to carry out further attacks.
https://capec.mitre.org/data/definitions/648.html →Open in CAPEC collection →| Product | Vendor | Status |
|---|---|---|
| grub2 | Tracked | |
| grub2 | Tracked | |
| grub2 | Tracked | |
| grub2 | Tracked | |
| grub2 | Tracked | |
| grub2 | Tracked | |
| grub2 | Tracked | |
| grub2 | * | Tracked |