
CVE-2022-40297 - Proof of Concept: Privilege escalation in Ubuntu Touch 16.04 - by PIN Bruteforce

[UPDATE 09.09.2022] I got new CVE for this vulnerability: CVE-2022-40297.
Ubuntu Touch allows you to "protect" devices with a 4-digit passcode. Such a code was set in a demonstration device. The problem is that the same 4-digit passcode then becomes a password that we can use with the sudo command and gain root privileges.
This means that a malicious application can do us double harm:
Follow me on Twitter @FilipKarc and on LinkedIn: LinkedIn.

