Privilege Escalation in PNP4Nagios through 0.6.26 via Unprivileged Account Ownership

Privilege Escalation in PNP4Nagios through 0.6.26 via Unprivileged Account Ownership

CVE-2017-16834 · HIGH Severity

AV:L/AC:L/AU:N/C:C/I:C/A:C

PNP4Nagios through 0.6.26 has /usr/bin/npcd and npcd.cfg owned by an unprivileged account but root code execution depends on these files, which allows local users to gain privileges by leveraging access to this unprivileged account.

Learn more about our Cis Benchmark Audit For Apple Ios.