CVE-2015-3222
HIGHOSSEC 2.7-2.8.1 - Local Privilege Escalation via syscheck/seechanges.c
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2015-3222. PoCs published by Andrew Widdersheim.
AI-analyzed exploit summary This is a detailed writeup explaining CVE-2015-3222, a local privilege escalation vulnerability in OSSEC HIDS versions 2.7 to 2.8.1. The vulnerability arises from improper handling of filenames in the syscheck daemon, allowing command injection via the diff command.
Description
syscheck/seechanges.c in OSSEC 2.7 through 2.8.1 on NIX systems allows local users to execute arbitrary code as root.
Exploits (1)
This is a detailed writeup explaining CVE-2015-3222, a local privilege escalation vulnerability in OSSEC HIDS versions 2.7 to 2.8.1. The vulnerability arises from improper handling of filenames in the syscheck daemon, allowing command injection via the diff command.
References (4)
Scores
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H