CVE-2015-3643

HIGH

usb-creator <0.2.38.3ubuntu0.1 - Privilege Escalation

Title source: llm
STIX 2.1

Description

usb-creator before 0.2.38.3ubuntu0.1 on Ubuntu 12.04 LTS, before 0.2.56.3ubuntu0.1 on Ubuntu 14.04 LTS, before 0.2.62ubuntu0.3 on Ubuntu 14.10, and before 0.2.67ubuntu0.1 on Ubuntu 15.04 allows local users to gain privileges by leveraging a missing call check_polkit for the KVMTest method.

Exploits (1)

exploitdb WORKING POC
by Tavis Ormandy · textlocallinux
https://www.exploit-db.com/exploits/36820

References (7)

Core 7
Core References
Third Party Advisory vendor-advisory x_refsource_ubuntu
https://usn.ubuntu.com/usn/usn-2576-2/
Exploit, Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/36820/
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2015/05/04/3
Third Party Advisory vendor-advisory x_refsource_ubuntu
https://usn.ubuntu.com/usn/usn-2576-1/
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/74304
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2015/04/22/12

Scores

CVSS v3 7.8
EPSS 0.0008
EPSS Percentile 24.1%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-264
Status published
Products (1)
usb-creator_project/usb-creator < 0.2.38.3
Published Sep 28, 2017
Tracked Since Feb 18, 2026