CVE-2023-2091 HIGH

CVE-2023-2091: KylinSoft youker-assistant adjust_cpufreq_scaling_governer os command injection

Vendor Kylinsoft
Product youker-assistant
Weakness CWE-78
Published April 15, 2023
Last update November 22, 2024

CVSS base score

7.8/10
Attack vector Local
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

A vulnerability classified as critical was found in KylinSoft youker-assistant on KylinOS. Affected by this vulnerability is the function adjust_cpufreq_scaling_governer. The manipulation leads to os command injection. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. Upgrading to version 3.1.4.13 is able to address this issue. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-226099.

Key dates

02Disclosure timeline

April 15, 2023 CVE published
November 22, 2024 Record updated