PT-2026-102618 · Canonical · Wsl-Pro-Service
CVSS v4.0
5.7
Medium
| Vector | AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
wsl-pro-service versions prior to 0.1.19ubuntu3
Description
A service component running as root within a WSL instance attaches the instance to Ubuntu Pro by executing the pro client and passing the Ubuntu Pro token as a command-line argument. On systems where
/proc is mounted without process-hiding mitigations like hidepid (the default in WSL), an unprivileged local user or process can read the token from /proc/<pid>/cmdline during the attachment process. This leak allows an attacker to use the token to attach other machines to the victim's subscription and gain unauthorized access to Ubuntu Pro services and repositories.Recommendations
Update wsl-pro-service to version 0.1.19ubuntu3 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wsl-Pro-Service