CVE-2015-3643

HIGH

usb-creator <0.2.38.3ubuntu0.1 - Privilege Escalation

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2015-3643. PoCs published by Tavis Ormandy.

AI-analyzed exploit summary This exploit leverages a D-Bus interface vulnerability in usb-creator to achieve local privilege escalation by injecting a malicious shared library via LD_PRELOAD, resulting in a setuid root shell.

Description

usb-creator before 0.2.38.3ubuntu0.1 on Ubuntu 12.04 LTS, before 0.2.56.3ubuntu0.1 on Ubuntu 14.04 LTS, before 0.2.62ubuntu0.3 on Ubuntu 14.10, and before 0.2.67ubuntu0.1 on Ubuntu 15.04 allows local users to gain privileges by leveraging a missing call check_polkit for the KVMTest method.

Exploits (1)

exploitdb WORKING POC
by Tavis Ormandy · textlocallinux
https://www.exploit-db.com/exploits/36820

This exploit leverages a D-Bus interface vulnerability in usb-creator to achieve local privilege escalation by injecting a malicious shared library via LD_PRELOAD, resulting in a setuid root shell.

Classification
Working Poc 100%
Attack Type
Lpe
Complexity
Moderate
Reliability
Reliable
Target: usb-creator (Ubuntu versions: Precise 0.2.38.3ubuntu, Trusty 0.2.56.3ubuntu, Utopic 0.2.62ubuntu0.2)
No auth needed
Prerequisites: Local access to the system · D-Bus access to com.ubuntu.USBCreator · Ability to write to /tmp
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (7)

Core 7
Core References
Third Party Advisory vendor-advisory x_refsource_ubuntu
https://usn.ubuntu.com/usn/usn-2576-2/
Exploit, Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/36820/
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2015/05/04/3
Third Party Advisory vendor-advisory x_refsource_ubuntu
https://usn.ubuntu.com/usn/usn-2576-1/
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/74304
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2015/04/22/12

Scores

CVSS v3 7.8
EPSS 0.0153
EPSS Percentile 71.4%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-264
Status published
Products (1)
usb-creator_project/usb-creator < 0.2.38.3
Published Sep 28, 2017
Tracked Since Feb 18, 2026