A vulnerability in GNOME Display Manager (gdm) could allow a standard user to create accounts with elevated privileges, giving a local attacker a path to execute code with administrator (root) privileges.
Although certain prerequisites are necessary, the bug is easy to exploit. The process involves running a few simple commands in the terminal and modifying general system settings that do not require elevated privileges.

Add new administrator
The exploit of the bug in gdm3 takes advantage of the crash of the AccountsService component, which keeps track of the users available on the system.
In addition to handling graphical display managers, gdm3 is also responsible for displaying the user login interface on Unix.
GitHub security researcher Kevin Backhouse has discovered a simple way to trick an already installed Ubuntu system into running the account configuration routine for a new system. This scenario requires an administrator to set up the machine and install applications.
The researcher found that “gdm3” triggered this sequence when the “accounts-daemon” of the AccountsService component was not running. A typical user should not be able to stop it.
However, Backhouse discovered two vulnerabilities in AccountsService that caused the component to be suspended (CVE-2020-16127) and the denial of user account privileges (CVE-2020-16126), allowing a typical user to terminate the daemon by sending it a delayed segmentation fault signal (kill -SIGSEGV).
The delay is necessary to allow time to exit the current session.
These two vulnerabilities affect Ubuntu 20.10, Ubuntu 20.04, Ubuntu 18.04, and Ubuntu 16.04.
For CVE-2020-16127, the researcher explains that it was caused by code added to the Ubuntu version of AccountService that is not present in the upstream version maintained by freedesktop.
Activation was possible by making a modification to the system Settings that did not require elevated privileges.
Without AccountsService running, gdm3 has no clue about the accounts that exist on the machine and provides the option to create a new one with root privileges, as in the case of a first-time installation
This bug is now reported as CVE-2020-16125 and is rated 7.2 out of 10, making it a serious vulnerability. It affects Ubuntu 20.10, Ubuntu 20.04, and Ubuntu 18.04.
Backhouse created a video showing how easy it was to exploit the gdm3 vulnerability in Ubuntu 20.04:
Backhouse published separate reports on Monday for these three vulnerabilities, which provide technical details. He reported them to Ubuntu and GNOME maintainers on October 17, and fixes are available in the latest code.
