aix.software.ibm.comConfirmation
http://aix.software.ibm.com/aix/efixes/security/bellmail_advisory.asc CVE-2016-8972
HIGH
IBM AIX 6.1/7.1/7.2 - 'Bellmail' Local Privilege Escalation
Record summary
CVE-2016-8972 has a selected CVSS score of 7.8 (high); EIP currently links 1 catalogued exploit and 1 curated repository PoC.
Description
IBM AIX 6.1, 7.1, and 7.2 could allow a local user to gain root privileges using a specially crafted command within the bellmail client. IBM APARs: IV91006, IV91007, IV91008, IV91010, IV91011.
Description source: CVE List
Exploitation context
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
| CVE List | 6.1 | affected | |
| 7.1 | affected | ||
| 7.2 | affected |
Proofs of concept
2Catalogued exploits
ExploitDBIBM AIX 6.1/7.1/7.2 - 'Bellmail' Local Privilege EscalationExploitDB exploitby Hector X. MonsegurNot analyzed1 file
Curated repository PoCs
GitHubCVE-2016-8972Curated repository PoCby RhinoSecurityLabsStars: 905Not analyzed3 files
References
594979vdb entry
http://www.securityfocus.com/bid/94979 1037480vdb entry
http://www.securitytracker.com/id/1037480 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2016-8972 40950exploit
https://www.exploit-db.com/exploits/40950