{"id":97197,"date":"2022-04-27T20:52:55","date_gmt":"2022-04-27T11:52:55","guid":{"rendered":"https:\/\/softantenna.com\/blog\/?p=97197"},"modified":"2022-04-27T20:52:55","modified_gmt":"2022-04-27T11:52:55","slug":"nimbuspwn-privilege-escalation-vulnerabilities","status":"publish","type":"post","link":"https:\/\/softantenna.com\/blog\/nimbuspwn-privilege-escalation-vulnerabilities\/","title":{"rendered":"Microsoft\u3001Linux\u306e\u7279\u6a29\u6607\u683c\u306e\u8106\u5f31\u6027\u300cNimbuspwn\u300d\u3092\u767a\u898b\u3059\u308b"},"content":{"rendered":"<p><img decoding=\"async\" style=\"display:block; margin-left:auto; margin-right:auto;\" src=\"https:\/\/softantenna.com\/blog\/wp-content\/uploads\/2022\/04\/pexels-dsd-689784.jpeg\" alt=\"Pexels dsd 689784\" title=\"pexels-dsd-689784.jpeg\" border=\"0\" width=\"1280\" height=\"853\" \/><\/p>\n<p>Microsoft\u306e\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u7814\u7a76\u8005\u304c\u3001Linux\u306e\u7279\u6a29\u6607\u683c\u306e\u8106\u5f31\u6027\u300cNimbuspwn\u300d\u3092\u767a\u898b\u3057\u305f\u3053\u3068\u304c\u308f\u304b\u308a\u307e\u3057\u305f(<a href=\"https:\/\/www.microsoft.com\/security\/blog\/2022\/04\/26\/microsoft-finds-new-elevation-of-privilege-linux-vulnerability-nimbuspwn\/\">Microsoft Security Blog<\/a>\u3001<a href=\"https:\/\/betanews.com\/2022\/04\/27\/microsoft-discovers-nimbuspwn-privilege-escalation-vulnerabilities-in-linux\/\">BetaNews<\/a>)\u3002<\/p>\n<p>\u8106\u5f31\u6027\u306fCVE-2022-29799\u304a\u3088\u3073CVE-2022-29800\u3068\u3057\u3066\u8ffd\u8de1\u3055\u308c\u3066\u304a\u308a\u3001Microsoft\u306f\u3001\u8106\u5f31\u6027\u304c\u30e9\u30f3\u30b5\u30e0\u30a6\u30a7\u30a2\u653b\u6483\u306a\u3069\u306b\u60aa\u7528\u3055\u308c\u308b\u53ef\u80fd\u6027\u304c\u3042\u308b\u3068\u8b66\u544a\u3057\u3066\u3044\u307e\u3059\u3002<\/p>\n<p>\u8106\u5f31\u6027\u3092\u767a\u898b\u3057\u305fMicrosoft 365 Defender Research Team\u306f\u3001\u300c\u591a\u304f\u306eLinux\u30c7\u30b9\u30af\u30c8\u30c3\u30d7\u306e\u30a8\u30f3\u30c9\u30dd\u30a4\u30f3\u30c8\u306b\u304a\u3044\u3066\u3001\u653b\u6483\u8005\u304c\u6a29\u9650\u3092\u6607\u683c\u3057\u3066root\u306b\u306a\u308b\u53ef\u80fd\u6027\u306e\u3042\u308b\u3001Nimbuspwn\u3068\u7dcf\u79f0\u3055\u308c\u308b\u8907\u6570\u306e\u8106\u5f31\u6027\u3092\u767a\u898b\u3057\u305f\u300d\u3068\u30d6\u30ed\u30b0\u8a18\u4e8b\u3067\u8aac\u660e\u3057\u3066\u3044\u307e\u3059\u3002<\/p>\n<p>\u3053\u308c\u3089\u306e\u8106\u5f31\u6027\u3092\u9023\u9396\u3057\u3066\u60aa\u7528\u3059\u308b\u3053\u3068\u3067Linux\u30b7\u30b9\u30c6\u30e0\u306e\u30eb\u30fc\u30c8\u6a29\u9650\u3092\u7372\u5f97\u3059\u308b\u3053\u3068\u304c\u3067\u304d\u3001\u653b\u6483\u8005\u306f\u3001\u30eb\u30fc\u30c8\u30d0\u30c3\u30af\u30c9\u30a2\u306e\u3088\u3046\u306a\u30da\u30a4\u30ed\u30fc\u30c9\u3092\u5c55\u958b\u3057\u3001\u4efb\u610f\u306e\u30eb\u30fc\u30c8\u30b3\u30fc\u30c9\u306e\u5b9f\u884c\u3092\u4ecb\u3057\u3066\u3001\u4ed6\u306e\u60aa\u610f\u306e\u3042\u308b\u30a2\u30af\u30b7\u30e7\u30f3\u3092\u5b9f\u884c\u3059\u308b\u3053\u3068\u304c\u53ef\u80fd\u3068\u306a\u308a\u307e\u3059\u3002\u6700\u7d42\u7684\u306b\u30de\u30eb\u30a6\u30a7\u30a2\u3084\u30e9\u30f3\u30b5\u30e0\u30a6\u30a7\u30a2\u306a\u3069\u3001\u3088\u308a\u60aa\u8cea\u306a\u8105\u5a01\u304c\u5b9f\u884c\u53ef\u80fd\u3068\u306a\u308b\u3053\u3068\u3067\u3001\u8106\u5f31\u306a\u30c7\u30d0\u30a4\u30b9\u306b\u5927\u304d\u306a\u5f71\u97ff\u3092\u4e0e\u3048\u308b\u53ef\u80fd\u6027\u304c\u3042\u308b\u3068\u306e\u3053\u3068\u3067\u3059\u3002<\/p>\n<blockquote><p>We discovered the vulnerabilities by listening to messages on the System Bus while performing code reviews and dynamic analysis on services that run as root, noticing an odd pattern in a systemd unit called networkd-dispatcher. Reviewing the code flow for networkd-dispatcher revealed multiple security concerns, including directory traversal, symlink race, and time-of-check-time-of-use race condition issues, which could be leveraged to elevate privileges and deploy malware or carry out other malicious activities. We shared these vulnerabilities with the relevant maintainers through Coordinated Vulnerability Disclosure (CVD) via Microsoft Security Vulnerability Research (MSVR). Fixes for these vulnerabilities, now identified as CVE-2022-29799 and CVE-2022-29800, have been successfully deployed by the maintainer of the networkd-dispatcher, Clayton Craft. We wish to thank Clayton for his professionalism and collaboration in resolving those issues.<\/p><\/blockquote>\n<p>Microsoft\u306f\u3001root\u6a29\u9650\u3067\u5b9f\u884c\u3055\u308c\u308b\u30b5\u30fc\u30d3\u30b9\u306e\u30b3\u30fc\u30c9\u30ec\u30d3\u30e5\u30fc\u3068\u52d5\u7684\u89e3\u6790\u3092\u884c\u3046\u969b\u3001System Bus\u4e0a\u306e\u30e1\u30c3\u30bb\u30fc\u30b8\u3092\u30ea\u30b9\u30cb\u30f3\u30b0\u3057\u3001\u300cnetworkd-dispatcher\u300d\u3068\u3044\u3046systemd \u30e6\u30cb\u30c3\u30c8\u306b\u5947\u5999\u306a\u30d1\u30bf\u30fc\u30f3\u304c\u3042\u308b\u3053\u3068\u306b\u6c17\u3065\u304d\u307e\u3059\u3002networkd-dispatcher\u306e\u30b3\u30fc\u30c9\u30d5\u30ed\u30fc\u3092\u30ec\u30d3\u30e5\u30fc\u3057\u305f\u3068\u3053\u308d\u3001\u30c7\u30a3\u30ec\u30af\u30c8\u30ea\u30c8\u30e9\u30d0\u30fc\u30b5\u30eb\u3001\u30b7\u30f3\u30dc\u30ea\u30c3\u30af\u30ea\u30f3\u30af\u306e\u7af6\u5408\u3001time-of-check-time-of-use \u306e\u7af6\u5408\u6761\u4ef6\u554f\u984c\u306a\u3069\u3001\u8907\u6570\u306e\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u4e0a\u306e\u61f8\u5ff5\u304c\u3042\u308b\u3053\u3068\u304c\u5224\u660e\u3057\u305f\u3068\u8aac\u660e\u3057\u3066\u3044\u307e\u3059\u3002<\/p>\n<p>Microsoft\u306f\u3001networkd-dispatcher\u3092\u4f7f\u7528\u3057\u3066\u3044\u308b\u30e6\u30fc\u30b6\u30fc\u306f\u3001\u30a4\u30f3\u30b9\u30bf\u30f3\u30b9\u3092\u66f4\u65b0\u3059\u308b\u5fc5\u8981\u304c\u3042\u308b\u3068\u30a2\u30c9\u30d0\u30a4\u30b9\u3057\u3066\u3044\u307e\u3059\u3002\u8106\u5f31\u6027\u306e\u8a73\u7d30\u306f<a href=\"https:\/\/www.microsoft.com\/security\/blog\/2022\/04\/26\/microsoft-finds-new-elevation-of-privilege-linux-vulnerability-nimbuspwn\/\">Microsoft\u306e\u30d6\u30ed\u30b0<\/a>\u3067\u78ba\u8a8d\u53ef\u80fd\u3067\u3059\u3002<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Microsoft\u306e\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u7814\u7a76\u8005\u304c\u3001Linux\u306e\u7279\u6a29\u6607\u683c\u306e\u8106\u5f31\u6027\u300cNimbuspwn\u300d\u3092\u767a\u898b\u3057\u305f\u3053\u3068\u304c\u308f\u304b\u308a\u307e\u3057\u305f(Microsoft Security Blog\u3001BetaNews)\u3002 \u8106\u5f31\u6027\u306fCVE-2022-2 [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":97198,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"swell_btn_cv_data":"","footnotes":""},"categories":[75],"tags":[37,87],"class_list":["post-97197","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-software","tag-linux","tag-microsoft"],"_links":{"self":[{"href":"https:\/\/softantenna.com\/blog\/wp-json\/wp\/v2\/posts\/97197","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/softantenna.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/softantenna.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/softantenna.com\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/softantenna.com\/blog\/wp-json\/wp\/v2\/comments?post=97197"}],"version-history":[{"count":0,"href":"https:\/\/softantenna.com\/blog\/wp-json\/wp\/v2\/posts\/97197\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/softantenna.com\/blog\/wp-json\/wp\/v2\/media\/97198"}],"wp:attachment":[{"href":"https:\/\/softantenna.com\/blog\/wp-json\/wp\/v2\/media?parent=97197"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/softantenna.com\/blog\/wp-json\/wp\/v2\/categories?post=97197"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/softantenna.com\/blog\/wp-json\/wp\/v2\/tags?post=97197"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}