Horizon Alert
Summary of the vulnerability and why it matters
This CVE involves a flaw in how NetworkManager handles certain network security settings, specifically for WPA-Enterprise connections. An unprivileged user on a system could potentially exploit this to bypass security checks, which could lead to the theft of user credentials if they connect to a malicious Wi-Fi network.
- Local users can bypass network security checks.
- Allows credential theft on rogue networks.
- Confirm relevance and exposure in your environment.
Attack Path
How an attacker could exploit the issue
An unprivileged local user can exploit this vulnerability by manipulating NetworkManager connection settings. This allows them to trick the system into trusting a malicious Wi-Fi network, potentially leading to the theft of user credentials.
- Requires local user access.
- Modifies network connection settings.
- Risks credential theft and network compromise.
Live Threat
Current exploitation, exposure, and threat context
This vulnerability could allow an unprivileged local user to bypass server certificate validation for WPA-Enterprise connections, potentially leading to credential theft. This occurs when the user manipulates connection profile settings to point CA paths at attacker-controlled directories, especially when supported by NetworkManager's configuration.
- User credentials and network access.
- Local user manipulates connection profile settings.
- Credential theft via rogue access point.
Operational Fix
Recommended remediation, mitigation, and detection steps
NetworkManager's handling of 802.1x certificate paths is susceptible to local privilege escalation, allowing unprivileged users to bypass server certificate validation and steal credentials. System owners and infrastructure teams should prioritize identifying affected systems, assessing their reachability and criticality, and confirming ownership before planning remediation.
- Network infrastructure and platform teams own this.
- Verify NetworkManager configuration and potential user manipulation.
- Plan remediation or mitigation based on exposure.