PT-2026-70085 · Mrtg+1 · Mrtg+1
CVSS v3.1
7.1
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
MRTG (affected versions not specified)
Description
A flaw exists when the MRTG daemon is started as a root user and subsequently drops privileges. A local, low-privileged attacker can exploit a symbolic link (symlink) following vulnerability by pre-placing a symlink in the process ID (PID) file path. This allows the attacker to trick the root process into changing the ownership of an arbitrary existing file to the daemon user, potentially leading to local privilege escalation and unauthorized access to or modification of sensitive files.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
LPE
Link Following
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mrtg
Rocky Linux