CVE-2017-8422
HIGHKDE kdelibs < 4.14.32 and KAuth < 5.34 - Authentication Bypass via CallerID Spoofing
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2017-8422. PoCs published by Stealth.
AI-analyzed exploit summary This exploit leverages a D-Bus authentication bypass in smb4k's mount helper to execute arbitrary commands as root. It crafts a malicious D-Bus message to inject a command into the mount process, leading to privilege escalation.
Description
KDE kdelibs before 4.14.32 and KAuth before 5.34 allow local users to gain root privileges by spoofing a callerID and leveraging a privileged helper app.
Exploits (1)
This exploit leverages a D-Bus authentication bypass in smb4k's mount helper to execute arbitrary commands as root. It crafts a malicious D-Bus message to inject a command into the mount process, leading to privilege escalation.
References (11)
Scores
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H