CIFSwitch: local privilege escalation in Linux via cifs-utils
Security researcher Asim Manizada has published details of CIFSwitch, a local privilege escalation issue in Linux tied to cifs-utils and the way authentication for CIFS/SMB file shares is handled. In vulnerable configurations, a local attacker can manipulate a request made by the CIFS authentication helper so that attacker-controlled code runs with elevated privileges. A proof of concept demonstrating root access has also been released.
According to the researcher the flaw has been present in Linux since 2007, but several preconditions must be met for practical exploitation. Some distributions block the exploit through default SELinux and AppArmor policies, while CentOS Stream 9 and Linux Mint variants, among others, have been confirmed exploitable in testing. A kernel patch and workarounds are available.
What this means for your organisation
This is not an external threat but an internal one. Once someone holds an ordinary user shell on a Linux server, whether through a compromised application or a stolen key, the path to root is short. That is the difference between a contained incident and a fully compromised system. Organisations running Linux servers that mount SMB shares should treat this as a real risk rather than a curiosity.
Berigo recommends
- Map which Linux servers have cifs-utils installed and actually mount CIFS/SMB shares.
- Roll out the kernel patch through your normal change cycle, and apply the published workarounds where immediate patching is not possible.
- Confirm that SELinux or AppArmor is in enforcing mode on production servers, not permissive.
- Remove cifs-utils where the package is installed but unused.
Source
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch