CVE-2025-41761

Publication date

2026-03-09 08:17:11

Family

CERTVDE

State

PUBLISHED

Description

A low‑privileged local attacker who gains access to the UBR service account (e.g., via SSH) can escalate privileges to obtain full system access. This is due to the service account being permitted to execute certain binaries (e.g., tcpdump and ip) with sudo.