PT-2026-95727 · Unknown · Networkmanager-L2Tp
CVSS v4.0
8.5
High
| Vector | AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
NetworkManager-l2tp versions 1.0 through 1.52.4
Description
A privilege escalation issue exists that allows local users with permission to create VPN connections to execute arbitrary code as root. An attacker can inject pppd options by using a crafted VPN username containing a double-quote character or whitespace. This allows the attacker to break out of the pppd options file quoting context and include the pppd plugin directive, which forces the privileged pppd process to load an attacker-controlled shared object.
Recommendations
Update NetworkManager-l2tp to version 1.52.6.
Exploit
Fix
LPE
Argument Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Networkmanager-L2Tp