CVE-2002-0572

FreeBSD <4.5 - Local Privilege Escalation

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2002-0572. PoCs published by phased.

AI-analyzed exploit summary This exploit leverages a BSD kernel bug where file descriptors 0-2 are not validated before exec()ing setuid images, allowing an attacker to manipulate standard I/O channels to gain root privileges via keyinit.

Description

FreeBSD 4.5 and earlier, and possibly other BSD-based operating systems, allows local users to write to or read from restricted files by closing the file descriptors 0 (standard input), 1 (standard output), or 2 (standard error), which may then be reused by a called setuid process that intended to perform I/O on normal files.

Exploits (1)

exploitdb WORKING POC VERIFIED
by phased · clocalbsd
https://www.exploit-db.com/exploits/21407

This exploit leverages a BSD kernel bug where file descriptors 0-2 are not validated before exec()ing setuid images, allowing an attacker to manipulate standard I/O channels to gain root privileges via keyinit.

Classification
Working Poc 95%
Attack Type
Lpe
Complexity
Trivial
Reliability
Reliable
Target: FreeBSD up to and including 4.5-RELEASE
No auth needed
Prerequisites: Local access to a vulnerable FreeBSD system
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (9)

Core 9
Core References
Third Party Advisory vdb-entry x_refsource_xf
http://www.iss.net/security_center/static/8920.php
Exploit, Patch, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/4568
US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/809347
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/6095
Third Party Advisory mailing-list x_refsource_vulnwatch
http://archives.neohapsis.com/archives/vulnwatch/2002-q2/0033.html
Patch, Vendor Advisory vendor-advisory x_refsource_freebsd
ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-02:23.stdio.asc
Third Party Advisory, US Government Resource third-party-advisory government-resource x_refsource_ciac
http://www.ciac.org/ciac/bulletins/m-072.shtml
Exploit, Patch, Vendor Advisory mailing-list x_refsource_bugtraq
http://online.securityfocus.com/archive/1/268970
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://online.securityfocus.com/archive/1/269102

Scores

EPSS 0.0155
EPSS Percentile 72.0%

Details

Status published
Products (14)
freebsd/freebsd 4.4 releng
freebsd/freebsd 4.5 release (2 CPE variants)
openbsd/openbsd 2.0
openbsd/openbsd 2.1
openbsd/openbsd 2.2
openbsd/openbsd 2.3
sun/solaris 2.5.1
sun/solaris 2.6
sun/solaris 7.0
sun/solaris 8.0
... and 4 more
Published Jul 03, 2002
Tracked Since Feb 18, 2026