PoC to demonstrate root permission hijacking by exploiting “systemd-run”
https://twitter.com/hackerfantastic/status/1785495587514638559
This isn't the only bug of course, it's not possible on Linux to read the environment of a root owned process but as systemd creates a service in the system slice, you can query D-BUS and learn sensitive information passed to the process env, such as API keys or other secrets.