CVE-2017-12579
HIGHHashiCorp Vagrant VMware Fusion < 4.0.24 - Unauthenticated Privilege Escalation via SUID Wrapper Binary
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2017-12579. PoCs published by Mark Wadham.
AI-analyzed exploit summary This exploit targets a privilege escalation vulnerability in Hashicorp's vagrant-vmware-fusion plugin version 4.0.24. It manipulates the execution flow of the plugin by modifying Ruby scripts to achieve root privileges via a SUID binary.
Description
An insecure suid wrapper binary in the HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) 4.0.24 and earlier allows a non-root user to obtain a root shell.
Exploits (1)
This exploit targets a privilege escalation vulnerability in Hashicorp's vagrant-vmware-fusion plugin version 4.0.24. It manipulates the execution flow of the plugin by modifying Ruby scripts to achieve root privileges via a SUID binary.
References (2)
Scores
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H