VulnerAlert



LINUX
MICROSOFT
SYSTEMS
26-06-2025 16:08

CVE-2025-53013 Vulnerabilidad documentada

5.2 MEDIUM
Tags
#using
#lte
#azure
#systems
#microsoft
#linux
#vulnerability
#/.net(.*)core/iU
#.net core
#affected
#problem
#issue
#error
#allow
#access
#affect
Descripción
Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. A vulnerability present in versions 0.9.10 through 0.9.16 allows a user to authenticate Linux host via Himmelblau using *invalid* Hello PIN, provided the offline. While gains access local system, Single Sign-On (SSO) fails due network being down inability issue tokens (due failure unlock key). The core lies incorrect assumption within `acquire_token_by_hello_for_business_key` function: it was expected return `TPMFail` error invalid key when offline, but instead, preceding nonce request resulted `RequestFailed` error, leading system erroneously transition offline success state without validating unlock. This impacts systems authentication operating with PIN enabled. Rocky 8 (and variants) are not affected by this vulnerability. problem resolved version 0.9.17. workaround available users who cannot immediately upgrade. Disabling setting `enable_hello = false` `/etc/himmelblau/himmelblau.conf` will mitigate
https://github.com/himmelblau-idm/himmelblau/commit/64b03739f1d5ee472b1cff3ed20ed9af1c65a6f8
https://github.com/himmelblau-idm/himmelblau/commit/78477d684df710d57c10091c87b92665cfac98ae
https://github.com/himmelblau-idm/himmelblau/security/advisories/GHSA-j93j-pwm6-p97j
Referencia
Link externo
Ver detalles

Fuente
https://nvd.nist.gov/vuln/detail/CVE-2025-53013
Resultados similares
Coincidentes en almenos en 50% de los tags
15-07-2025
Interlock ransomware adopts new FileFix attack to push malware Hackers have adopted the new tec...
Ver información
15-07-2025
Linux : Oracle Linux 7 ELSA-2025-9741 important: perl-File-Find-Rule security issue The followi...
Ver información
Icons made by Freepik from www.flaticon.com
Este Proyecto fue cofinanciado por el Consejo Nacional de Ciencia y Tecnología (CONACYT) a través del PROINNOVA 2021/2023
Proyecto realizado por