Exploitation Summary
EIP tracks 1 public exploit for CVE-2011-5330. PoCs published by Metasploit.
AI-analyzed exploit summary This exploit leverages a vulnerability in Distributed Ruby (DRb) to execute arbitrary syscalls on a remote Linux system. It creates a file, writes a shell script payload to it, and executes it using syscalls, achieving remote code execution.
Description
Distributed Ruby (aka DRuby) 1.8 mishandles the sending of syscalls.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Metasploit · rubyremotelinux
https://www.exploit-db.com/exploits/17031
This exploit leverages a vulnerability in Distributed Ruby (DRb) to execute arbitrary syscalls on a remote Linux system. It creates a file, writes a shell script payload to it, and executes it using syscalls, achieving remote code execution.
Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target:
Distributed Ruby (DRb)
No auth needed
Prerequisites:
DRb service exposed and accessible · Network access to the target
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026
Full analysis →
References (1)
Core 1
Core References
Exploit, Third Party Advisory, VDB Entry x_refsource_misc
https://www.exploit-db.com/exploits/17031
Scores
CVSS v3
9.8
EPSS
0.0032
EPSS Percentile
56.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
Status
published
Products (1)
distributed_ruby_project/distributed_ruby
1.8
Published
Nov 18, 2019
Tracked Since
Feb 18, 2026