
PoC for CVE-2024-48990
CVE-2024-48990 is a local privilege escalation vulnerability found in the needrestart utility. The vuln exists in versions prior to 3.8. The service, which runs as root during events like package installations, insecurely scans all running processes. When it finds a Python process, it reads and trusts the PYTHONPATH environment variable from that process.
An unprivileged local attacker can hijack the PYTHONPATH on a "lure" process. When needrestart runs, it will find it, adopting the malicious path, and then execute the attacker's code with root privileges.
git clone https://github.com/Mr-DJ/CVE-2024-48990
cd CVE-2024-48990
chmod +x exploit.sh
needrestart is executed by root), popping a root shell.needrestart to version 3.8 or a patched version from your distributionnosuid and noexec options.CVE: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-48990
Original Advisory: Qualys - LPEs in needrestart
NIST: NVD-CVE-2024-48990