CVE-2017-5618
HIGHGNU screen < 4.5.1 - Unauthenticated Arbitrary File Write via Logfile Permissions
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2017-5618. PoCs published by RXDarkee.
AI-analyzed exploit summary This is a functional local privilege escalation exploit for GNU Screen 4.5.0 (CVE-2017-5618) that leverages shared library hijacking via ld.so.preload manipulation to gain root access. The exploit creates a malicious library and a setuid root shell, then tricks Screen into overwriting /etc/ld.so.preload to load the library.
Description
GNU screen before 4.5.1 allows local users to modify arbitrary files and consequently gain root privileges by leveraging improper checking of logfile permissions.
Exploits (1)
This is a functional local privilege escalation exploit for GNU Screen 4.5.0 (CVE-2017-5618) that leverages shared library hijacking via ld.so.preload manipulation to gain root access. The exploit creates a malicious library and a setuid root shell, then tricks Screen into overwriting /etc/ld.so.preload to load the library.
References (6)
Scores
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H