Microsoft Discovers Linux Vulnerabilities That Could Allow Attackers to Gain Root Access

Microsoft 365 Defender Research team has discovered the vulnerabilities that are tracked as CVE-2022-29799 and CVE-2022-29800.

Advertisement
By Jagmeet Singh | Updated: 27 April 2022 18:53 IST
Highlights
  • Microsoft researchers detailed the flaws in a blog post
  • Linux distributions with networkd-dispatcher are at risk
  • The developer of the system component fixed the issues

Hackers may use multiple scripts to exploit the vulnerabilities on a Linux system

Photo Credit: Reuters

Microsoft has revealed that it discovered a list of vulnerabilities that could allow bad actors to gain root system rights on Linux systems. Collectively called Nimbuspwn, the vulnerabilities could potentially be leveraged by attackers as a vector for root access by more sophisticated threats including malware and ransomware, the software giant said. The security flaws exist in a system component that is widely available on Linux distributions. Fixes for the reported vulnerabilities have been deployed by the maintainer of the component.

In a detailed blog post, Microsoft said that the vulnerabilities discovered by the Microsoft 365 Defender Research team could be grouped together to gain root privileges on Linux systems and allow attackers to execute ransomware attacks or malicious actions using arbitrary code.

The vulnerabilities, tracked as CVE-2022-29799 and CVE-2022-29800, were found in the component called networkd-dispatcher, which helps provide network status updates. It runs as root when a system starts to dispatch network status changes and run scripts to respond to a new network status.

Advertisement

However, it was discovered that the system component included a method "_run_hooks_for_state" that allows hackers to gain access to the “/etc/networkd-dispatcher” base directory. The method essentially exposes the Linux system to the directory traversal vulnerability, which is identified as CVE-2022-29799, by not sanitising the OperationalState or the AdministrativeState, according to the Microsoft researchers.

Advertisement

The same method is also found to have the Time-of-check-time-of-use (TOCTOU) race condition flaw, which is tracked as CVE-2022-29800. This particular flaw allows attackers to replace scripts that networkd-dispatcher believes to be owned by root with the ones that contain malicious code, the researchers said.

An attacker may use multiple malicious scripts one after another to exploit the vulnerability.

Advertisement

Microsoft researchers shared a proof-of-concept where they highlighted that in three attempts, they were able to win the race condition flaw and successfully plant their files.

As ArsTechnica notes, a hacker with minimal access to a vulnerable system can exploit the reported vulnerabilities to gain full root access.

Advertisement

Microsoft Principal Security Researcher Jonathan Bar Or told Gadgets 360 that the flaws have been fixed in the latest version of network-dispatcher. Users will be able to find the new version in a systemd update on their Linux machines. Otherwise, they can deploy the patches by manually install the latest network-dispatcher build.

Users can determine the existence of the vulnerabilities on their systems by using the details shared by Microsoft researchers. If the machines are vulnerable, it is highly recommended to look for the fixes.


Asus India's Arnold Su joins this week's Orbital, the Gadgets 360 podcast, to talk about how the PC maker is planning to grow its presence in the country. Orbital is available on Spotify, Gaana, JioSaavn, Google Podcasts, Apple Podcasts, Amazon Music and wherever you get your podcasts.
Affiliate links may be automatically generated - see our ethics statement for details.
 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Redmi Note 15 Pro Series 5G Launched in India With These Features
  2. Adobe Express Premium Is Now Free for One Year for All Airtel Users
  3. Sarvam Maya OTT Release Date: When and Where to Watch it Online?
  4. Samsung Galaxy S26 Ultra Could Cost Less than Its Predecessor
  5. Realme P4 Power 5G First Impressions
  6. Champion OTT Release: Where To Watch Roshan Meka's Telugu Sports Drama Online?
  7. NASA's TESS Captures First Images of Rare Interstellar Comet 3I/ATLAS
  8. Nothing Skips 2026 Flagship Launch; Will Focus on Phone 4a, Audio Products
  9. Red Magic 11 Air Launched in Global Markets With ICE Cooling System
  10. Vivo X200T Review
  1. CERN Experiments Confirm Early Universe Behaved Like a Near-Perfect Fluid
  2. NASA’s TESS Captures First Images of Rare Interstellar Comet 3I/ATLAS
  3. Daredevil: Born Again Season 2 OTT Release Date Confirmed: When and Where to Watch it Online?
  4. The Wrecking Crew Starring Jason Momoa and Dave Bautista Now Streaming: What You Need to Know
  5. Redmi Buds 8 Pro Launched With ANC, Hi-Res Audio and Up to 36 Hours of Total Battery Life
  6. Samsung Galaxy Tab S12+ Surfaces on IMEI Database, Could Launch Soon
  7. Champion OTT Release: Where To Watch Roshan Meka’s Telugu Sports Drama Online?
  8. Nothing Won't Launch a Flagship Model in 2026; Company to Focus on Nothing Phone 4a and Audio Products, Carl Pei Says
  9. Redmi Turbo 5 Max Launched With 9,000mAh Battery, Redmi Turbo 5 Tags Along: Price, Specifications
  10. Ponies Starring Emilia Clarke and Haley Lu Richardson Now Available for Streaming
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.