CVE-2016-4997
HIGHLinux Kernel 4.6.3 Netfilter Privilege Escalation
Title source: metasploitExploitation Summary
EIP tracks 3 public exploits for CVE-2016-4997.
PoCs published by Metasploit, Qian Zhang, h00die <[email protected]>, vnik, Jesse Hertz, Tim Newsham, including Metasploit module exploits/linux/local/netfilter_priv_esc_ipv4.
AI-analyzed exploit summary This Metasploit module exploits CVE-2016-4997, a Linux kernel netfilter privilege escalation vulnerability affecting Ubuntu 16.04 with kernel 4.4.0-21-generic. It compiles and executes a C-based exploit to gain elevated privileges by manipulating netfilter structures.
Description
The compat IPT_SO_SET_REPLACE and IP6T_SO_SET_REPLACE setsockopt implementations in the netfilter subsystem in the Linux kernel before 4.6.3 allow local users to gain privileges or cause a denial of service (memory corruption) by leveraging in-container root access to provide a crafted offset value that triggers an unintended decrement.
Exploits (3)
This Metasploit module exploits CVE-2016-4997, a Linux kernel netfilter privilege escalation vulnerability affecting Ubuntu 16.04 with kernel 4.4.0-21-generic. It compiles and executes a C-based exploit to gain elevated privileges by manipulating netfilter structures.
This exploit leverages a vulnerability in the IPv6 netfilter subsystem of the Linux kernel (CVE-2016-4997) to escalate privileges via an IP6T_SO_SET_REPLACE compat setsockopt call. It requires the ip6_tables module to be loaded and demonstrates a successful local privilege escalation to root.
This Metasploit module exploits a netfilter bug in Linux kernels before 4.6.3, specifically targeting Ubuntu 16.04 with kernel 4.4.0-21-generic. It leverages a privilege escalation vulnerability (CVE-2016-4997) by compiling and executing a crafted exploit on the target system.
References (43)
Scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H