
Local privilege escalation exploit for CVE-2022-37706 targeting the Enlightenment window manager's SUID binary, enabling root shell access through crafted input manipulation.
The CVE-2022-37706 vulnerability is related to the Enlightenment window manager, specifically the enlightenment_sys binary. This binary has the SUID (Set User ID) bit enabled, meaning it can be executed with elevated privileges (usually as the root user).
enlightenment_sys binary in the Enlightenment window manager.To protect against this vulnerability, users should update to a patched version of Enlightenment where the SUID permissions are properly managed, or remove the SUID bit from the vulnerable binary (chmod u-s enlightenment_sys).
This vulnerability highlights the risks of improper privilege management in setuid binaries.