Exploitation Summary
EIP tracks 1 public exploit for CVE-2016-10010. PoCs published by Google Security Research.
AI-analyzed exploit summary This exploit leverages OpenSSH's UNIX domain socket forwarding when privilege separation is disabled, allowing a non-root user to gain root privileges via systemd manipulation. The PoC demonstrates binding to a UNIX domain socket and injecting an LD_PRELOAD environment variable to escalate privileges.
Description
sshd in OpenSSH before 7.4, when privilege separation is not used, creates forwarded Unix-domain sockets as root, which might allow local users to gain privileges via unspecified vectors, related to serverloop.c.
Exploits (1)
This exploit leverages OpenSSH's UNIX domain socket forwarding when privilege separation is disabled, allowing a non-root user to gain root privileges via systemd manipulation. The PoC demonstrates binding to a UNIX domain socket and injecting an LD_PRELOAD environment variable to escalate privileges.
References (13)
Scores
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H