python: local privilege escalation via search path in Windows
Published Mar 7, 2022
7.0
HIGHCVSS 3.1
EPSS 1.36%
Description
In Python before 3.10.3 on Windows, local users can gain privileges because the search path is inadequately secured. The installer may allow a local attacker to add user-writable directories to the system search path. To exploit, an administrator must have installed Python for all users and enabled PATH entries. A non-administrative user can trigger a repair that incorrectly adds user-writable paths into PATH, enabling search-path hijacking of other users and system services. This affects Python (CPython) through 3.7.12, 3.8.x through 3.8.12, 3.9.x through 3.9.10, and 3.10.x through 3.10.2.
Affected products
No data.
Configuration 1
- ≤ 3.7.12
- ≥ 3.8.0 · ≤ 3.8.12
- ≥ 3.9.0 · ≤ 3.9.10
- ≥ 3.10.0 · ≤ 3.10.2
- 3.11.0
- 3.11.0
- 3.11.0
- 3.11.0
- 3.11.0
- 3.11.0
Configuration 2
- n/a
- n/a
No data.
Red Hat Enterprise Linux 10
python3.12
Not affected
Red Hat Enterprise Linux 7
python
Not affected
Red Hat Enterprise Linux 7
python3
Not affected
Red Hat Enterprise Linux 8
gimp:flatpak/python2
Not affected
Red Hat Enterprise Linux 8
python3
Not affected
Red Hat Enterprise Linux 8
python3.11
Not affected
Red Hat Enterprise Linux 8
python3.12
Not affected
Red Hat Enterprise Linux 8
python36:3.6/python36
Not affected
Red Hat Enterprise Linux 8
python39-devel:3.9/python39
Not affected
Red Hat Enterprise Linux 8
python39:3.9/python39
Not affected
Red Hat Enterprise Linux 9
python3.11
Not affected
Red Hat Enterprise Linux 9
python3.12
Not affected
Red Hat Enterprise Linux 9
python3.9
Not affected
Red Hat Enterprise Linux AI (RHEL AI)
rhelai1/bootc-nvidia-rhel9
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | python3.12 | Not affected | n/a |
| Red Hat Enterprise Linux 7 | python | Not affected | n/a |
| Red Hat Enterprise Linux 7 | python3 | Not affected | n/a |
| Red Hat Enterprise Linux 8 | gimp:flatpak/python2 | Not affected | n/a |
| Red Hat Enterprise Linux 8 | python3 | Not affected | n/a |
| Red Hat Enterprise Linux 8 | python3.11 | Not affected | n/a |
| Red Hat Enterprise Linux 8 | python3.12 | Not affected | n/a |
| Red Hat Enterprise Linux 8 | python36:3.6/python36 | Not affected | n/a |
| Red Hat Enterprise Linux 8 | python39-devel:3.9/python39 | Not affected | n/a |
| Red Hat Enterprise Linux 8 | python39:3.9/python39 | Not affected | n/a |
| Red Hat Enterprise Linux 9 | python3.11 | Not affected | n/a |
| Red Hat Enterprise Linux 9 | python3.12 | Not affected | n/a |
| Red Hat Enterprise Linux 9 | python3.9 | Not affected | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) | rhelai1/bootc-nvidia-rhel9 | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This vulnerability is specific to certain versions of Python on Windows systems. No Red Hat products are affected.
References (7)
- https://access.redhat.com/security/cve/CVE-2022-26488 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2316527 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-31046 Advisory
- https://mail.python.org/archives/list/security-announce%40python.org/thread/657Z4XULWZNIY5FRP3OWXHYKUSIH6DMN/ x_refsource_MISC
- https://nvd.nist.gov/vuln/detail/CVE-2022-26488
- https://security.netapp.com/advisory/ntap-20220419-0005/ x_refsource_CONFIRMThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2022-26488
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2022-26488 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2316527 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-31046 | Advisory | |
| https://mail.python.org/archives/list/security-announce%40python.org/thread/657Z4XULWZNIY5FRP3OWXHYKUSIH6DMN/ | x_refsource_MISC | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-26488 | ||
| https://security.netapp.com/advisory/ntap-20220419-0005/ | x_refsource_CONFIRMThird Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2022-26488 |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
GitHub
No data