Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-24050


MariaDB CONNECT Storage Engine Use-After-Free Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of MariaDB. Authentication is required to exploit this vulnerability. The specific flaw exists within the processing of SQL queries. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of the service account. Was ZDI-CAN-16207.


Published

2022-02-18T20:15:17.873

Last Modified

2024-11-21T06:49:44.010

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.8 (HIGH)

CVSSv2 Vector

AV:L/AC:L/Au:N/C:P/I:P/A:P

  • Access Vector: LOCAL
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

3.9

Impact Score

6.4

Weaknesses
  • Type: Secondary
    CWE-416

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application mariadb mariadb < 10.2.42 Yes
Application mariadb mariadb < 10.3.33 Yes
Application mariadb mariadb < 10.4.23 Yes
Application mariadb mariadb < 10.5.14 Yes
Application mariadb mariadb < 10.6.6 Yes
Application mariadb mariadb < 10.7.2 Yes
Application mariadb mariadb 10.8.0 Yes
Operating System fedoraproject fedora 34 Yes
Operating System fedoraproject fedora 35 Yes
Operating System fedoraproject fedora 36 Yes

References