PT-2025-46540 · Altair · Altair Grid Engine
CVE-2025-40763
·
Publicado
2025-11-11
·
Atualizado
2025-11-11
CVSS v3.1
7.8
Alta
| Vetor | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Altair Grid Engine versions prior to 2026.0.0
Description
The software does not properly validate environment variables when loading shared libraries, which can allow for path hijacking through malicious library substitution. A local attacker could potentially execute arbitrary code with superuser privileges by manipulating the environment variable and placing a malicious library in a controlled path.
Recommendations
Update to version 2026.0.0 or later.
Correção
LPE
Uncontrolled Search Path Element
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Altair Grid Engine