Exploitation Summary
EIP tracks 1 public exploit for CVE-2016-8972. PoCs published by Hector X. Monsegur.
AI-analyzed exploit summary This exploit leverages a vulnerability in IBM AIX's bellmail binary to escalate privileges to root by manipulating the /etc/suid_profile file. It creates a SUID root shell in /tmp and executes it after triggering the vulnerability via mail delivery.
Description
IBM AIX 6.1, 7.1, and 7.2 could allow a local user to gain root privileges using a specially crafted command within the bellmail client. IBM APARs: IV91006, IV91007, IV91008, IV91010, IV91011.
Exploits (1)
This exploit leverages a vulnerability in IBM AIX's bellmail binary to escalate privileges to root by manipulating the /etc/suid_profile file. It creates a SUID root shell in /tmp and executes it after triggering the vulnerability via mail delivery.
References (4)
Scores
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H