CVE-2010-3895

IBM OmniFind Enterprise Edition < 9.1 - Local Privilege Escalation via esRunCommand

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2010-3895. PoCs published by Fatih Kilic.

AI-analyzed exploit summary This exploit leverages two SUID binaries (`esRunCommand` and `estaskwrapper`) in IBM software to escalate privileges to root. The `esRunCommand` directly executes commands as root, while `estaskwrapper` can be tricked into executing a malicious binary named `estasklight` via environment variable manipulation.

Description

esRunCommand in IBM OmniFind Enterprise Edition before 9.1 allows local users to gain privileges by specifying an arbitrary command name as the first argument.

Exploits (1)

exploitdb WORKING POC
by Fatih Kilic · textlocalmultiple
https://www.exploit-db.com/exploits/15475

This exploit leverages two SUID binaries (`esRunCommand` and `estaskwrapper`) in IBM software to escalate privileges to root. The `esRunCommand` directly executes commands as root, while `estaskwrapper` can be tricked into executing a malicious binary named `estasklight` via environment variable manipulation.

Classification
Working Poc 100%
Attack Type
Lpe
Complexity
Trivial
Reliability
Reliable
Target: IBM software (specific version not mentioned)
No auth needed
Prerequisites: Access to the system with the vulnerable IBM software installed · Presence of SUID binaries `/opt/IBM/es/bin/esRunCommand` and `/opt/IBM/es/bin/estaskwrapper`
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/514688/100/0/threaded
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/15475
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/44740
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2010/2933

Scores

EPSS 0.0078
EPSS Percentile 51.3%

Details

CWE
CWE-264
Status published
Products (4)
ibm/omnifind 8.0
ibm/omnifind 8.4
ibm/omnifind 8.5
ibm/omnifind < 9.0
Published Nov 12, 2010
Tracked Since Feb 18, 2026