CVE-2016-9566
HIGHNagios < 4.2.3 - Privilege Escalation via Symlink Attack on Log File
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2016-9566. PoCs published by Dawid Golunski.
AI-analyzed exploit summary This exploit leverages a symlink attack on Nagios Core's log file to manipulate `/etc/ld.so.preload` and escalate privileges to root. It compiles a shared library to set SUID permissions on a backdoor shell when executed by a SUID binary like `sudo`.
Description
base/logging.c in Nagios Core before 4.2.4 allows local users with access to an account in the nagios group to gain root privileges via a symlink attack on the log file. NOTE: this can be leveraged by remote attackers using CVE-2016-9565.
Exploits (1)
This exploit leverages a symlink attack on Nagios Core's log file to manipulate `/etc/ld.so.preload` and escalate privileges to root. It compiles a shared library to set SUID permissions on a backdoor shell when executed by a SUID binary like `sudo`.
References (18)
Scores
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H