CVE-2024-36041
Kde
CVE-2024-36041: A critical security flaw exists in KDE Plasma Workspace before versions 5.27.11.1 and 6.0.5.1. This vulnerability in KSmserver allows unauthorized local connections due to insufficient host-based authentication via ICE. An attacker on the same machine can exploit this to access the session manager. This can lead to arbitrary code execution as the victim user on the next system boot by manipulating the session restore feature and using the /tmp directory. Despite a CVSS score of 7.8, indicating a high severity, the SOCRadar Vulnerability Risk Score (SVRS) of 44 suggests a moderate level of immediate risk. While not critical based on SVRS, patching is still advised to prevent potential local privilege escalation and unauthorized access to user sessions. This issue is significant because it allows attackers to potentially gain control over a user's account and execute malicious code, compromising the entire system.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.