Record summary

CVE-2017-6554 has a selected CVSS score of 7.2 (high); EIP currently links 2 catalogued exploits.

Description

pmmasterd in Quest Privilege Manager before 6.0.0.061, when configured as a policy server, allows remote attackers to write to arbitrary files and consequently execute arbitrary code with root privileges via an ACT_NEWFILESENT action.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
2

Proofs of concept

2

Catalogued exploits

ExploitDBQuest Privilege Manager 6.0.0 - Arbitrary File WriteExploitDB exploitby m0tNot analyzed1 file
ExploitDB

PoC details
MetasploitQuest Privilege Manager pmmasterd Buffer OverflowMetasploit exploitby m0tNot analyzed1 file

Ruby · linked to 2 vulnerabilities

Metasploit

PoC details

References

6