{"id":113173,"date":"2022-04-27T05:43:07","date_gmt":"2022-04-27T07:43:07","guid":{"rendered":"https:\/\/teknomers.com\/fr\/microsoft-decouvre-de-nouvelles-failles-descalade-de-privileges-dans-le-systeme-dexploitation-linux\/"},"modified":"2022-04-27T05:43:11","modified_gmt":"2022-04-27T07:43:11","slug":"microsoft-decouvre-de-nouvelles-failles-descalade-de-privileges-dans-le-systeme-dexploitation-linux","status":"publish","type":"post","link":"https:\/\/teknomers.com\/fr\/microsoft-decouvre-de-nouvelles-failles-descalade-de-privileges-dans-le-systeme-dexploitation-linux\/","title":{"rendered":"Microsoft d\u00e9couvre de nouvelles failles d&#8217;escalade de privil\u00e8ges dans le syst\u00e8me d&#8217;exploitation Linux"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both\"><\/div>\n<p>Microsoft a d\u00e9voil\u00e9 mardi un ensemble de deux vuln\u00e9rabilit\u00e9s d&#8217;escalade de privil\u00e8ges dans le syst\u00e8me d&#8217;exploitation Linux qui pourraient potentiellement permettre aux acteurs de la menace de mener un \u00e9ventail d&#8217;activit\u00e9s n\u00e9fastes.<\/p>\n<p>Appel\u00e9s collectivement &#8220;<b>Nimbuspwn<\/b>&#8220;, les failles&#8221; peuvent \u00eatre encha\u00een\u00e9es pour obtenir des privil\u00e8ges root sur les syst\u00e8mes Linux, permettant aux attaquants de d\u00e9ployer des charges utiles, comme une porte d\u00e9rob\u00e9e root, et d&#8217;effectuer d&#8217;autres actions malveillantes via l&#8217;ex\u00e9cution arbitraire de code root &#8220;, Jonathan Bar Or de l&#8217;\u00e9quipe de recherche Microsoft 365 Defender <a rel=\"nofollow noopener\" href=\"https:\/\/www.microsoft.com\/security\/blog\/2022\/04\/26\/microsoft-finds-new-elevation-of-privilege-linux-vulnerability-nimbuspwn\/\" target=\"_blank\">mentionn\u00e9<\/a> dans un rapport.<\/p>\n<div class=\"ad_two clear\"><a rel=\"nofollow noopener\" href=\"https:\/\/go.thn.li\/mset1\" target=\"_blank\" title=\"CyberSecurity\"><img loading=\"lazy\" decoding=\"async\" alt=\"La cyber-s\u00e9curit\u00e9\" class=\"lazyload\" src=\"https:\/\/teknomers.com\/fr\/wp-content\/uploads\/2022\/02\/TrickBot-Gang-est-susceptible-de-modifier-ses-operations-pour-passer.png\" width=\"300\" height=\"250\" \/><\/a><\/div>\n<p>En plus de cela, les d\u00e9fauts &#8211; suivis comme <b>CVE-2022-29799 et CVE-2022-29800<\/b> \u2013 pourrait \u00e9galement \u00eatre utilis\u00e9 comme vecteur d&#8217;acc\u00e8s root pour d\u00e9ployer des menaces plus sophistiqu\u00e9es telles que les ransomwares.<\/p>\n<p>Les vuln\u00e9rabilit\u00e9s sont enracin\u00e9es dans un <a rel=\"nofollow noopener\" href=\"https:\/\/en.wikipedia.org\/wiki\/Systemd\" target=\"_blank\">systemd<\/a> composant appel\u00e9 <a rel=\"nofollow noopener\" href=\"https:\/\/manpages.ubuntu.com\/manpages\/focal\/man8\/networkd-dispatcher.8.html\" target=\"_blank\">r\u00e9seaud-r\u00e9partiteur<\/a>un <a rel=\"nofollow noopener\" href=\"https:\/\/gitlab.com\/craftyguy\/networkd-dispatcher\" target=\"_blank\">programme d\u00e9mon<\/a> pour le service syst\u00e8me du gestionnaire de r\u00e9seau con\u00e7u pour r\u00e9partir les changements d&#8217;\u00e9tat du r\u00e9seau.<\/p>\n<div class=\"separator\" style=\"clear: both\"><img decoding=\"async\" alt=\"Failles d'escalade de privil\u00e8ges sous Linux\" border=\"0\" data-original-height=\"700\" data-original-width=\"728\" src=\"https:\/\/teknomers.com\/fr\/wp-content\/uploads\/2022\/04\/1651045387_407_Microsoft-decouvre-de-nouvelles-failles-descalade-de-privileges-dans-le.jpg\" title=\"Failles d'escalade de privil\u00e8ges sous Linux\" \/><\/div>\n<p>Plus pr\u00e9cis\u00e9ment, ils concernent une combinaison de <a rel=\"nofollow noopener\" href=\"https:\/\/en.wikipedia.org\/wiki\/Directory_traversal_attack\" target=\"_blank\">parcours de r\u00e9pertoire<\/a> (CVE-2022-29799), <a rel=\"nofollow noopener\" href=\"https:\/\/en.wikipedia.org\/wiki\/Symlink_race\" target=\"_blank\">course de lien symbolique (aka symlink)<\/a>et <a rel=\"nofollow noopener\" href=\"https:\/\/en.wikipedia.org\/wiki\/Time-of-check_to_time-of-use\" target=\"_blank\">de l&#8217;heure de v\u00e9rification \u00e0 l&#8217;heure d&#8217;utilisation<\/a> (CVE-2022-29800) failles, conduisant \u00e0 un sc\u00e9nario o\u00f9 un adversaire contr\u00f4lant un voleur <a rel=\"nofollow noopener\" href=\"https:\/\/en.wikipedia.org\/wiki\/D-Bus\" target=\"_blank\">D-Bus<\/a> <a rel=\"nofollow noopener\" href=\"https:\/\/unit42.paloaltonetworks.com\/usbcreator-d-bus-privilege-escalation-in-ubuntu-desktop\/\" target=\"_blank\">un service<\/a> peut planter et ex\u00e9cuter des portes d\u00e9rob\u00e9es malveillantes sur les terminaux compromis.<\/p>\n<div class=\"ad_two clear\"><a rel=\"nofollow noopener\" href=\"https:\/\/go.thn.li\/crowdsec-tour-d\" target=\"_blank\" title=\"CyberSecurity\"><img loading=\"lazy\" decoding=\"async\" alt=\"La cyber-s\u00e9curit\u00e9\" class=\"lazyload\" src=\"https:\/\/thehackernews.com\/new-images\/img\/b\/R29vZ2xl\/AVvXsEj6zHdXd3qpCksF0nkMkrjsOzaw-cxZGPHWoTEp9y7VPIeyPBFGsmIyIX8NTkqI1IDqnIXYnsZuIh4rc9f8TNUn7ndAZqtXc-t58X2oueTaL4Ijb4hgH-b183QvQ0ienXIipuOsqeLP5b8I2prKmp0RWvdZQgnKehVRKbqRQpin1JgfwlZeE_IB4EmesQ\/s1600\/crowdsec-728.jpg\" width=\"728\" height=\"90\" \/><\/a><\/div>\n<p>Il est fortement recommand\u00e9 aux utilisateurs de networkd-dispatcher de mettre \u00e0 jour leurs instances vers la derni\u00e8re version afin d&#8217;att\u00e9nuer le potentiel r\u00e9sultant de l&#8217;exploitation des failles.<\/p>\n<p>&#8220;Le nombre croissant de vuln\u00e9rabilit\u00e9s sur les environnements Linux souligne la n\u00e9cessit\u00e9 d&#8217;une surveillance renforc\u00e9e du syst\u00e8me d&#8217;exploitation de la plate-forme et de ses composants&#8221;, a d\u00e9clar\u00e9 Bar Or.<\/p>\n<p>&#8220;Ce bombardement constant d&#8217;attaques couvrant un large \u00e9ventail de plates-formes, d&#8217;appareils et d&#8217;autres domaines souligne la n\u00e9cessit\u00e9 d&#8217;une approche de gestion des vuln\u00e9rabilit\u00e9s compl\u00e8te et proactive qui peut identifier et att\u00e9nuer davantage les exploits et les probl\u00e8mes jusqu&#8217;alors inconnus.&#8221;<\/p>\n<p><\/p>\n<\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/thehackernews.com\/2022\/04\/microsoft-discovers-new-privilege.html\" rel=\"nofollow noopener\" target=\"_blank\">ttn-fr-57<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Microsoft a d\u00e9voil\u00e9 mardi un ensemble de deux vuln\u00e9rabilit\u00e9s d&#8217;escalade de privil\u00e8ges dans le syst\u00e8me d&#8217;exploitation Linux qui pourraient potentiellement permettre aux acteurs de la menace de mener un \u00e9ventail d&#8217;activit\u00e9s n\u00e9fastes. Appel\u00e9s collectivement &#8220;Nimbuspwn&#8220;, les failles&#8221; peuvent \u00eatre encha\u00een\u00e9es pour obtenir des privil\u00e8ges root sur les syst\u00e8mes Linux, permettant aux attaquants de d\u00e9ployer des [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":113174,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[4168,4158,4165,4161,429,12680,28044,5858,4806,4157,4159,4171,4170,18088,4167,8362,4160,120,4163,4162,53446,4172,4169,2622,4166,4164],"class_list":["post-113173","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-technologie","tag-comment-pirater","tag-cyber-actualites","tag-cyber-attaques","tag-cyber-mises-a-jour","tag-dans","tag-decouvre","tag-descalade","tag-dexploitation","tag-failles","tag-lactualite-de-la-cybersecurite","tag-lactualite-de-la-cybersecurite-aujourdhui","tag-lactualite-des-hackers","tag-la-securite-des-informations","tag-linux","tag-logiciel-malveillant-de-ransomware","tag-microsoft","tag-mises-a-jour-de-la-cybersecurite","tag-nouvelles","tag-nouvelles-de-piratage","tag-nouvelles-de-pirates","tag-privileges","tag-securite-informatique","tag-securite-internet","tag-systeme","tag-violation-de-donnees","tag-vulnerabilite-logicielle"],"_links":{"self":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts\/113173","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/comments?post=113173"}],"version-history":[{"count":0,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts\/113173\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/media\/113174"}],"wp:attachment":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/media?parent=113173"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/categories?post=113173"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/tags?post=113173"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}