CVE-2022-1804
CVSS 3.1 Score 5.5 of 10 (medium)
Details
Published Mar 25, 2025
Updated: Mar 27, 2025
CWE ID 269
Summary
CVE-2022-1804 is a vulnerability affecting the Red Hat Product "Accounts Service." This issue arises due to the service no longer dropping privileges when writing .pam_environment files. An attacker with local access could exploit this vulnerability by modifying these files, potentially leading to privilege escalation and unauthorized system access. It is recommended that users update their Accounts Service to a version that addresses this issue to mitigate the risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.