packetstormsecurity.com
http://packetstormsecurity.com/files/142095/Quest-Privilege-Manager-6.0.0-Arbitrary-File-Write.html CVE-2017-6554
HIGH
Quest Privilege Manager 6.0.0 - Arbitrary File Write
Record summary
CVE-2017-6554 has a selected CVSS score of 7.2 (high); EIP currently links 2 catalogued exploits.
Description
pmmasterd in Quest Privilege Manager before 6.0.0.061, when configured as a policy server, allows remote attackers to write to arbitrary files and consequently execute arbitrary code with root privileges via an ACT_NEWFILESENT action.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 2
Proofs of concept
2Catalogued exploits
ExploitDBQuest Privilege Manager 6.0.0 - Arbitrary File WriteExploitDB exploitby m0tNot analyzed1 file
MetasploitQuest Privilege Manager pmmasterd Buffer OverflowMetasploit exploitby m0tNot analyzed1 file
References
697686vdb entry
http://www.securityfocus.com/bid/97686 0xdeadface.wordpress.com
https://0xdeadface.wordpress.com/2017/04/07/multiple-vulnerabilities-in-quest-privilege-manager-6-0-0-xx-cve-2017-6553-cve-2017-6554 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2017-6554 support.oneidentity.comConfirmation
https://support.oneidentity.com/privilege-manager-for-unix/kb/SOL133824 41861exploit
https://www.exploit-db.com/exploits/41861