CVE-2018-18629
HIGHKeybase < 2.8.0-20181023124437 - Untrusted Search Path Privilege Escalation via keybase-redirector
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2018-18629. PoCs published by mirchr.
AI-analyzed exploit summary This exploit leverages a PATH environment variable manipulation in the setuid root binary `keybase-redirector` to execute a malicious `fusermount` binary as root. The PoC demonstrates arbitrary command execution by creating a file `/w00t` with root privileges.
Description
An issue was discovered in the Keybase command-line client before 2.8.0-20181023124437 for Linux. An untrusted search path vulnerability in the keybase-redirector application allows a local, unprivileged user on Linux to gain root privileges via a Trojan horse binary.
Exploits (1)
This exploit leverages a PATH environment variable manipulation in the setuid root binary `keybase-redirector` to execute a malicious `fusermount` binary as root. The PoC demonstrates arbitrary command execution by creating a file `/w00t` with root privileges.
References (3)
Scores
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H