CVE-2022-33912

    Dashboard / Vulnerabilities / CVE-2022-33912

    CVE-2022-33912

    Published: 17 Jun 2022Last Modified: 12 Aug 2026

    Summary:

    Details: A permission issue affects users that deployed the shipped version of the Checkmk Debian package. Packages created by the agent bakery (enterprise editions only) were not affected. Using the shipped version of the agents, the maintainer scripts located at /var/lib/dpkg/info/ will be owned by the user and the group with ID 1001. If such a user exists on the system, they can change the content of these files (which are then executed by root). This leads to a local privilege escalation on the monitored host. Version 1.6 through 1.6.9p29, version 2.0 through 2.0.0p26, version 2.1 through 2.1.0p3, and version 2.2.0i1 are affected.

    Affected packages

    Package

    Name:

    Purl:

    Affected ranges

    Type: GIT

    Events:

    Introduced- d5ccd5ecc956e665aca80f3c486f7fa46f409424
    Fixed -None

    Affected versions

    1.6.0-NA
    1.6.0-b1
    1.6.0-b10
    1.6.0-b12
    1.6.0-b3
    1.6.0-b4
    1.6.0-b5
    1.6.0-b9
    1.6.0-p11
    1.6.0-p13
    1.6.0-p14
    1.6.0-p15
    1.6.0-p16
    1.6.0-p19
    1.6.0-p2
    1.6.0-p20
    1.6.0-p21
    1.6.0-p22
    1.6.0-p23
    1.6.0-p24
    1.6.0-p25
    1.6.0-p26
    1.6.0-p27
    1.6.0-p28
    1.6.0-p29

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    CVE-2022-33912 | CVE-DB