CVE-2006-6131

Kerio WebSTAR <5.4.2 - Privilege Escalation

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2006-6131. PoCs published by Kevin Finisterre.

AI-analyzed exploit summary This exploit targets a vulnerability in Kerio WebSTAR by injecting a malicious dynamic library (libucache.dylib) into the target binary's execution path. The library contains a constructor that spawns a root shell by escalating privileges.

Description

Untrusted search path vulnerability in (1) WSAdminServer and (2) WSWebServer in Kerio WebSTAR (4D WebSTAR Server Suite) 5.4.2 and earlier allows local users with webstar privileges to gain root privileges via a malicious libucache.dylib helper library in the current working directory.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Kevin Finisterre · perllocalosx
https://www.exploit-db.com/exploits/2788

This exploit targets a vulnerability in Kerio WebSTAR by injecting a malicious dynamic library (libucache.dylib) into the target binary's execution path. The library contains a constructor that spawns a root shell by escalating privileges.

Classification
Working Poc 95%
Attack Type
Lpe
Complexity
Moderate
Reliability
Reliable
Target: Kerio WebSTAR 5.4.2
Auth required
Prerequisites: Access to the webstar user or admin group · Ability to write to /tmp · Presence of vulnerable Kerio WebSTAR binaries
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (9)

Core 9
Core References
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/21123
Exploit vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1017239
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/30308
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/451832/100/200/threaded
Exploit vdb-entry x_refsource_osvdb
http://www.osvdb.org/30450
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/1921
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/4539
Exploit, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/22906

Scores

EPSS 0.0085
EPSS Percentile 53.3%

Details

Status published
Products (15)
kerio/webstar 4.0
kerio/webstar 5.1.2
kerio/webstar 5.1.3
kerio/webstar 5.2
kerio/webstar 5.2.1
kerio/webstar 5.2.2
kerio/webstar 5.2.3
kerio/webstar 5.2.4
kerio/webstar 5.3
kerio/webstar 5.3.1
... and 5 more
Published Nov 28, 2006
Tracked Since Feb 18, 2026