CVE-2017-8422

HIGH

KDE Kauth < 5.33 - Authentication Bypass by Spoofing

Title source: rule

Description

KDE kdelibs before 4.14.32 and KAuth before 5.34 allow local users to gain root privileges by spoofing a callerID and leveraging a privileged helper app.

Exploits (1)

exploitdb WORKING POC
by Stealth · clocallinux
https://www.exploit-db.com/exploits/42053

Scores

CVSS v3 7.8
EPSS 0.0037
EPSS Percentile 59.1%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-290
Status published
Products (2)
kde/kauth < 5.33
kde/kdelibs < 4.14.31
Published May 17, 2017
Tracked Since Feb 18, 2026