Horizon Alert
Summary of the vulnerability and why it matters
A security vulnerability has been identified in Incus, a system for managing containers and virtual machines. This issue could allow an attacker with limited access to write arbitrary files to the host system, potentially leading to the execution of malicious commands. The vulnerability is present in versions prior to 7.1.0, with version 7.1.0 addressing the problem.
- Improper validation allows file writes.
- Could lead to host system compromise.
- Confirm relevance and ensure software is updated.
Attack Path
How an attacker could exploit the issue
An attacker with authenticated access to Incus could exploit this vulnerability by tricking the system into using a malicious compression algorithm when creating a backup. This allows the attacker to inject arbitrary commands into the system's command line, potentially leading to the ability to write any file on the host system, which could then be leveraged for arbitrary command execution.
- Authenticated access required.
- Malicious backup compression algorithm.
- Arbitrary file write, command execution.
Live Threat
Current exploitation, exposure, and threat context
When supported by the advisory, an attacker with low privileges could exploit this vulnerability to write arbitrary files to the host system, potentially leading to the execution of arbitrary commands. This could impact the integrity and availability of the host system.
- Host system files.
- Improper validation of backup algorithm.
- Arbitrary command execution.
Operational Fix
Recommended remediation, mitigation, and detection steps
Incus is a system container and virtual machine manager, indicating that platform or infrastructure teams are likely responsible for its management and security. The first practical step is to identify all instances of Incus, determine their exposure and criticality, and then assign ownership for remediation.
- Platform/Infrastructure teams own resolution.
- Verify Incus instance exposure and criticality.
- Plan remediation based on identified risk.