跳转到帖子

invscout RPM Privilege Escalation

recommended_posts

发布于
  • Members

invscout RPM Privilege Escalation

Disclosed
04/24/2023
Created
05/18/2023

Description

This module exploits a command injection vulnerability in IBM AIX invscout set-uid root utility present in AIX 7.2 and earlier. The undocumented -rpm argument can be used to install an RPM file; and the undocumented -o argument passes arguments to the rpm utility without validation, leading to command injection with effective-uid root privileges. This module has been tested successfully on AIX 7.2.

Author(s)

Platform

AIX,Unix

Architectures

cmd

Development

  • Source Code
  • History
  • 查看数 696
  • 已创建
  • 最后回复

参与讨论

你可立刻发布并稍后注册。 如果你有帐户,立刻登录发布帖子。
注意:你的帖子需要版主批准后才能看到。

游客
回帖…