Sploitus

CVE-2024-48990

15 known exploits for CVE-2024-48990

Qualys discovered that needrestart, before version 3.8, allows local attackers to execute arbitrary code as root by tricking needrestart into running the Python interpreter with an attacker-controlled PYTHONPATH environment variable.

Needrestart Project Needrestart
< 3.8
Fix
Available
CVSS 3.1
7.8 HIGH
EPSS
19.9% (97th percentile)
Weakness
CWE-427
NVD status
Modified
Published
2024-11-19

Workaround

Edit /etc/needrestart/needrestart.conf so that the following line appears after "# Disable interpreter scanners." and reboot: $nrconf{interpscan} = 0;

CVE-2024-48990 at NVD
Authoritative description, scoring and affected products

15 known exploits for CVE-2024-48990

Proof-of-concept code and exploit modules indexed by Sploitus

Exploit for Uncontrolled Search Path Element in Needrestart_Project Needrestart
2026-02-13 BLUEBERRYP1LLGITHUB
Exploit for Uncontrolled Search Path Element in Needrestart_Project Needrestart
2025-12-19 tahsinunluturkGITHUB
Exploit for Uncontrolled Search Path Element in Needrestart_Project Needrestart
2025-10-31 LoaxertGITHUB
Exploit for Uncontrolled Search Path Element in Needrestart_Project Needrestart
2025-10-30 Mr-DJGITHUB
Exploit for Uncontrolled Search Path Element in Needrestart_Project Needrestart
2025-10-28 Serner77GITHUB
Exploit for Uncontrolled Search Path Element in Needrestart_Project Needrestart
2025-10-28 mladicstefanGITHUB
Exploit for Uncontrolled Search Path Element in Needrestart_Project Needrestart
2025-02-16 ten-opsGITHUB
Exploit for Uncontrolled Search Path Element in Needrestart_Project Needrestart
2024-12-18 NullByte-7w7GITHUB
Exploit for Uncontrolled Search Path Element in Needrestart_Project Needrestart
2024-11-25 ally-petittGITHUB
Exploit for Uncontrolled Search Path Element in Needrestart_Project Needrestart
2024-11-24 pentestfunctionsGITHUB
needrestart Local Privilege Escalation Vulnerability
2024-11-24 QualysZDTPerl
needrestart Local Privilege Escalation
2024-11-22 Qualys Security AdvisoryPACKETSTORMPerl
Exploit for Uncontrolled Search Path Element in Needrestart_Project Needrestart
2024-11-21 ns989GITHUB
Exploit for Uncontrolled Search Path Element in Needrestart_Project Needrestart
2024-11-20 makuga01GITHUB
Ubuntu needrestart Privilege Escalation
2024-11-19 h00die, makuga01, qualysMETASPLOITRuby