{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aneedrestart_projectneedrestart/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:needrestart_project:needrestart:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.8,"id":"CVE-2024-48990"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["NeedRestart"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["NeedRestart"],"content_html":"\u003cp\u003eThis threat involves local privilege escalation on Linux systems where attackers exploit the way Python handles module loading. By manipulating the PYTHONPATH environment variable, an adversary can influence a privileged process to import a malicious shared object instead of the legitimate library. This technique is specifically documented in the exploitation of CVE-2024-48990, a vulnerability in the 'NeedRestart' utility which checks for pending service restarts on Linux distributions. When NeedRestart runs with root privileges, it can be coerced into loading a crafted 'importlib/\u003cstrong\u003einit\u003c/strong\u003e.so' file placed in an attacker-controlled directory. If successful, the attacker gains arbitrary code execution with the permissions of the calling process, typically root. Defenders should monitor for the creation of shared object files with specific naming conventions in non-standard system directories.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker gains low-privileged access to the target Linux system.\u003c/li\u003e\n\u003cli\u003eAttacker identifies the use of the NeedRestart utility (CVE-2024-48990) or similar vulnerable processes.\u003c/li\u003e\n\u003cli\u003eAttacker creates a malicious shared object file named 'importlib/\u003cstrong\u003einit\u003c/strong\u003e.so'.\u003c/li\u003e\n\u003cli\u003eAttacker writes this malicious library to an attacker-controlled directory outside of standard system paths (e.g., /tmp or user home directories).\u003c/li\u003e\n\u003cli\u003eAttacker sets or modifies the PYTHONPATH environment variable to include the directory containing the malicious library.\u003c/li\u003e\n\u003cli\u003eAttacker triggers the execution of the privileged NeedRestart utility.\u003c/li\u003e\n\u003cli\u003eThe utility, due to the manipulated PYTHONPATH, loads the attacker's 'importlib/\u003cstrong\u003einit\u003c/strong\u003e.so' module instead of the legitimate one.\u003c/li\u003e\n\u003cli\u003eThe malicious code within the shared object executes with root privileges, leading to full system compromise.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this technique results in full local privilege escalation to the root user. This allows an attacker to bypass standard security controls, access sensitive system data, install persistent backdoors, and execute arbitrary commands across the affected Linux environment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eDeploy the provided Sigma detection rule to monitor for unauthorized 'importlib/\u003cstrong\u003einit\u003c/strong\u003e.so' file creation events.\u003c/li\u003e\n\u003cli\u003ePatch the NeedRestart utility immediately to remediate CVE-2024-48990 on all vulnerable Linux endpoints.\u003c/li\u003e\n\u003cli\u003eAudit environment variable configurations for high-privileged service accounts to ensure PYTHONPATH is not overly permissive.\u003c/li\u003e\n\u003cli\u003eEnable Sysmon for Linux Event ID 11 logging to capture filesystem creation events required for the detection logic.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-08-07T15:16:23Z","date_published":"2026-08-07T15:16:23Z","id":"https://feed.craftedsignal.io/briefs/2026-08-linux-pythonpath-privesc/","summary":"Attackers can escalate privileges on Linux systems by abusing the PYTHONPATH environment variable to force privileged processes, specifically the NeedRestart utility (CVE-2024-48990), to load malicious shared objects.","title":"Linux Privilege Escalation via PYTHONPATH Manipulation","url":"https://feed.craftedsignal.io/briefs/2026-08-linux-pythonpath-privesc/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:needrestart_project:needrestart:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}