CVE-2019-19520
HIGHOpenBSD 6.6 - Privilege Escalation via LIBGL_DRIVERS_PATH Environment Variable
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2019-19520. PoCs published by retrymp3.
AI-analyzed exploit summary This repository contains a functional privilege escalation exploit for OpenBSD targeting CVE-2019-19520 and CVE-2019-19522. It leverages the xlock binary's SGID 'auth' group vulnerability to escalate privileges to root via S/Key or YubiKey manipulation.
Description
xlock in OpenBSD 6.6 allows local users to gain the privileges of the auth group by providing a LIBGL_DRIVERS_PATH environment variable, because xenocara/lib/mesa/src/loader/loader.c mishandles dlopen.
Exploits (1)
This repository contains a functional privilege escalation exploit for OpenBSD targeting CVE-2019-19520 and CVE-2019-19522. It leverages the xlock binary's SGID 'auth' group vulnerability to escalate privileges to root via S/Key or YubiKey manipulation.
References (7)
Scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H