CVE-2014-2533

BlackBerry QNX Neutrino RTOS <6.5.x - Privilege Escalation

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 3 public exploits for CVE-2014-2533. PoCs published by Metasploit, cenobyte, cenobyte, Tim Brown, bcoles, including Metasploit module exploits/qnx/local/ifwatchd_priv_esc.

AI-analyzed exploit summary This Metasploit module exploits a privilege escalation vulnerability in QNX's ifwatchd (CVE-2014-2533) by leveraging its failure to drop privileges when executing user-supplied scripts via the '-A' argument. It writes a malicious script to a writable directory and triggers it using ifwatchd, resulting in arbitrary command execution as root.

Description

/sbin/ifwatchd in BlackBerry QNX Neutrino RTOS 6.4.x and 6.5.x allows local users to gain privileges by providing an arbitrary program name as a command-line argument.

Exploits (3)

exploitdb WORKING POC VERIFIED
by Metasploit · rubylocallinux
https://www.exploit-db.com/exploits/45575

This Metasploit module exploits a privilege escalation vulnerability in QNX's ifwatchd (CVE-2014-2533) by leveraging its failure to drop privileges when executing user-supplied scripts via the '-A' argument. It writes a malicious script to a writable directory and triggers it using ifwatchd, resulting in arbitrary command execution as root.

Classification
Working Poc 100%
Attack Type
Lpe
Complexity
Trivial
Reliability
Reliable
Target: QNX Neutrino 6.4.x, 6.5.x (ifwatchd)
No auth needed
Prerequisites: Access to a writable directory (e.g., /tmp) · ifwatchd must be setuid root
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by cenobyte · bashlocalqnx
https://www.exploit-db.com/exploits/32153

This exploit leverages a privilege escalation vulnerability in QNX's ifwatchd service, which executes user-supplied scripts with root privileges. The script creates a malicious arrival-script that spawns a setuid root shell, then triggers it via ifwatchd.

Classification
Working Poc 100%
Attack Type
Lpe
Complexity
Trivial
Reliability
Reliable
Target: QNX 6.4.x/6.5.x ifwatchd
No auth needed
Prerequisites: Access to a vulnerable QNX system · Ability to execute /sbin/ifwatchd
devstral-2 · analyzed Feb 18, 2026 Full analysis →
metasploit WORKING POC EXCELLENT
by cenobyte, Tim Brown, bcoles · rubypocunix
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/qnx/local/ifwatchd_priv_esc.rb

This Metasploit module exploits a privilege escalation vulnerability in QNX's ifwatchd SUID executable by leveraging the '-A' argument to execute arbitrary commands as root. It writes a malicious script to a writable directory and triggers it via ifwatchd.

Classification
Working Poc 100%
Attack Type
Lpe
Complexity
Trivial
Reliability
Reliable
Target: QNX Neutrino 6.4.x, 6.5.x (ifwatchd)
No auth needed
Prerequisites: Access to a QNX system with vulnerable ifwatchd · Write permissions in a directory (default /tmp)
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (6)

Core 6
Core References
Mailing List mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2014/Mar/124
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/45575/
Mailing List mailing-list x_refsource_bugtraq
http://seclists.org/bugtraq/2014/Mar/66
Mailing List mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2014/Mar/98
Mailing List mailing-list x_refsource_bugtraq
http://seclists.org/bugtraq/2014/Mar/88
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/32153/

Scores

EPSS 0.2625
EPSS Percentile 96.4%

Details

CWE
CWE-264
Status published
Products (2)
blackberry/qnx_neutrino_rtos 6.4.1
blackberry/qnx_neutrino_rtos 6.5.0 (2 CPE variants)
Published Mar 18, 2014
Tracked Since Feb 18, 2026