CVE-2017-9232
CRITICALJuju < 1.25.12, 2.0.x < 2.0.4, 2.1.x < 2.1.3 - Privilege Escalation via UNIX Domain Socket
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2017-9232.
PoCs published by Metasploit, Ryan Beisner, David Ames (@thedac), bcoles, including Metasploit module exploits/linux/local/juju_run_agent_priv_esc.
AI-analyzed exploit summary This Metasploit module exploits a privilege escalation vulnerability in Juju agent systems by leveraging improperly secured UNIX domain sockets to execute arbitrary commands as root. It checks for vulnerable units, uploads a payload executable, and executes it via the privileged socket.
Description
Juju before 1.25.12, 2.0.x before 2.0.4, and 2.1.x before 2.1.3 uses a UNIX domain socket without setting appropriate permissions, allowing privilege escalation by users on the system to root.
Exploits (2)
This Metasploit module exploits a privilege escalation vulnerability in Juju agent systems by leveraging improperly secured UNIX domain sockets to execute arbitrary commands as root. It checks for vulnerable units, uploads a payload executable, and executes it via the privileged socket.
This Metasploit module exploits a privilege escalation vulnerability in Juju agent systems by leveraging improperly secured UNIX domain sockets to execute arbitrary commands as root. It targets versions prior to 1.25.12, 2.0.x before 2.0.4, and 2.1.x before 2.1.3.
References (3)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H