CVE-2017-7358
HIGHLightDM < 1.22.0 - Path Traversal and Privilege Escalation via Guest Account Logout
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2017-7358. PoCs published by G. Geshev, JonPichel.
AI-analyzed exploit summary This exploit leverages a race condition in LightDM's guest account creation script to escalate privileges to root. The attacker races the creation of a temporary directory to replace it with a symbolic link, ultimately hijacking the guest user's home directory and executing arbitrary code as root.
Description
In LightDM through 1.22.0, a directory traversal issue in debian/guest-account.sh allows local attackers to own arbitrary directory path locations and escalate privileges to root when the guest user logs out.
Exploits (2)
This exploit leverages a race condition in LightDM's guest account creation script to escalate privileges to root. The attacker races the creation of a temporary directory to replace it with a symbolic link, ultimately hijacking the guest user's home directory and executing arbitrary code as root.
This PoC exploits CVE-2017-7358, a race condition in the LightDM guest session handling, to achieve local privilege escalation (LPE) by manipulating directory symlinks and user creation timing. The exploit involves monitoring /tmp for guest session directories and replacing them with symlinks to gain root access.
References (6)
Scores
CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H