Ubuntu 20.04 local privilege escalation (LPE)
Channel:
Subscribers:
14,700
Published on ● Video Link: https://www.youtube.com/watch?v=b-JSicZ_kho
A security researcher has told how he accidentally achieved local privilege escalation (LPE) on the Ubuntu operating system by chaining two vulnerabilities to gain root access.
Ubuntu, the Debian-based Linux distribution, ships in three versions: desktop, server, and core for IoT devices.
The LPE vulnerability, which only impacts the desktop version, is the result of two bugs – a denial-of-service (DoS) vulnerability and a timeout flaw that was discovered in the user registration process.
When combined, the vulnerabilities allowed a malicious user to create a new administrator account without having the relevant permissions, enabling them to completely take over devices running the OS.