{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3amicrosoftwindows_defender_for_endpointlinux/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:microsoft:windows_defender_for_endpoint:*:*:*:*:*:linux:*:*","cpe:2.3:a:microsoft:windows_defender_for_endpoint:-:*:*:*:*:linux:*:*"],"_cs_cves":[{"cvss":5.5,"id":"CVE-2022-29799"},{"cvss":4.7,"id":"CVE-2022-29800"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["networkd-dispatcher"],"_cs_severities":["low"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Systemd"],"content_html":"\u003cp\u003eNimbuspwn, identified via CVE-2022-29799 and CVE-2022-29800, involves significant security flaws within the networkd-dispatcher service on Linux systems. The vulnerability resides in how the service handles D-Bus messages and performs directory traversal when scripts are executed. An attacker can exploit this by manipulating the service to execute arbitrary scripts with elevated privileges, effectively escalating access to root. This threat is particularly concerning for defenders as it allows for full system compromise, the installation of persistent backdoors, and the potential deployment of further malicious payloads. The exploitation mechanism relies on triggering the service's logic to traverse directories to an attacker-controlled path, where malicious code is then executed by the service as the root user.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker gains low-privileged access to the target Linux system.\u003c/li\u003e\n\u003cli\u003eAttacker identifies the running networkd-dispatcher service as a target for privilege escalation.\u003c/li\u003e\n\u003cli\u003eAttacker creates a malicious script or payload to be executed with elevated privileges.\u003c/li\u003e\n\u003cli\u003eAttacker utilizes directory traversal techniques (e.g., using '../*' sequences) to bypass intended path restrictions.\u003c/li\u003e\n\u003cli\u003eAttacker triggers a D-Bus message or service function that forces networkd-dispatcher to execute the attacker's script from the traversed path.\u003c/li\u003e\n\u003cli\u003eThe networkd-dispatcher service executes the malicious script under the context of the root user.\u003c/li\u003e\n\u003cli\u003eAttacker successfully gains root-level access for further exploitation or persistence.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows a low-privileged user to escalate to root, granting them full control over the affected system. This facilitates the deployment of persistent threats, theft of sensitive information, and potential lateral movement within the network. Although specific victim counts are not cited, the ubiquity of systemd-based Linux distributions makes this a critical risk for enterprise environments.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDeploy the provided Sigma rule to monitor for suspicious command-line patterns involving networkd-dispatcher.\u003c/li\u003e\n\u003cli\u003ePatch all affected Linux distributions to the latest version, as the vendor has released security updates addressing these vulnerabilities.\u003c/li\u003e\n\u003cli\u003eEnable Sysmon for Linux process-creation logging to ensure full visibility into command-line arguments.\u003c/li\u003e\n\u003cli\u003eConduct a threat hunt for historical occurrences of directory traversal strings originating from the networkd-dispatcher process.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-07T15:16:13Z","date_published":"2026-08-07T15:16:13Z","id":"https://feed.craftedsignal.io/briefs/2026-08-nimbuspwn-privilege-escalation/","summary":"Nimbuspwn refers to a collection of Linux privilege escalation vulnerabilities in the networkd-dispatcher service that attackers can exploit via directory traversal to achieve root-level code execution.","title":"Nimbuspwn Privilege Escalation Vulnerability","url":"https://feed.craftedsignal.io/briefs/2026-08-nimbuspwn-privilege-escalation/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:microsoft:windows_defender_for_endpoint:*:*:*:*:*:linux:*:*","version":"https://jsonfeed.org/version/1.1"}