CVE-2009-1786

IBM AIX 5.3 and 6.1 - Arbitrary File Creation or Overwrite via MALLOCDEBUG Log File Symlink

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2009-1786. PoCs published by Affix, inking.

AI-analyzed exploit summary This exploit leverages a vulnerability in IBM AIX's libc MALLOCDEBUG feature to overwrite arbitrary files with elevated permissions. By setting specific environment variables, an attacker can create or overwrite files with 777 permissions when a setuid root binary is executed.

Description

The malloc subsystem in libc in IBM AIX 5.3 and 6.1 allows local users to create or overwrite arbitrary files via a symlink attack on the log file associated with the MALLOCDEBUG environment variable.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Affix · bashlocalaix
https://www.exploit-db.com/exploits/9306

This exploit leverages a vulnerability in IBM AIX's libc MALLOCDEBUG feature to overwrite arbitrary files with elevated permissions. By setting specific environment variables, an attacker can create or overwrite files with 777 permissions when a setuid root binary is executed.

Classification
Working Poc 90%
Attack Type
Lpe
Complexity
Trivial
Reliability
Reliable
Target: IBM AIX 5.3 ML 5 and later (libc.a)
No auth needed
Prerequisites: Access to an IBM AIX system with vulnerable libc · Ability to set environment variables · Presence of a setuid root binary to trigger the vulnerability
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by inking · textwebappsphp
https://www.exploit-db.com/exploits/33001

This exploit leverages a cross-site scripting (XSS) vulnerability in Kingsoft Internet Security 9's WebShield feature to execute arbitrary commands. The payload is URL-encoded and triggers a JavaScript `CallCFunc` method to execute a system command via `calc.exe`.

Classification
Working Poc 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: Kingsoft Internet Security 9 (WebShield 1.1.0.62 and prior)
No auth needed
Prerequisites: Victim must visit a malicious URL
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (17)

Core 17
Core References
Various Sources vendor-advisory x_refsource_aixapar
http://www.ibm.com/support/docview.wss?uid=isg1IZ50517
Various Sources vendor-advisory x_refsource_aixapar
http://www.ibm.com/support/docview.wss?uid=isg1IZ50500
Patch, Vendor Advisory x_refsource_confirm
http://aix.software.ibm.com/aix/efixes/security/libc_advisory.asc
Various Sources vendor-advisory x_refsource_aixapar
http://www.ibm.com/support/docview.wss?uid=isg1IZ50445
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6276
Various Sources vendor-advisory x_refsource_aixapar
http://www.ibm.com/support/docview.wss?uid=isg1IZ50447
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/54617
Various Sources vendor-advisory x_refsource_aixapar
http://www.ibm.com/support/docview.wss?uid=isg1IZ50121
Third Party Advisory third-party-advisory x_refsource_idefense
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=802
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/35034
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/9306
Patch vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1022261
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2009/1380
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/50636
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/35146
Various Sources vendor-advisory x_refsource_aixapar
http://www.ibm.com/support/docview.wss?uid=isg1IZ50129
Various Sources vendor-advisory x_refsource_aixapar
http://www.ibm.com/support/docview.wss?uid=isg1IZ50139

Scores

EPSS 0.0067
EPSS Percentile 47.0%

Details

CWE
CWE-362
Status published
Products (2)
ibm/aix 5.3
ibm/aix 6.1
Published May 26, 2009
Tracked Since Feb 18, 2026