CVE-2020-8794
CRITICALOpenSMTPD OOB Read Local Privilege Escalation
Title source: metasploitExploitation Summary
EIP tracks 3 public exploits for CVE-2020-8794.
PoCs published by Metasploit, Qualys Corporation, Qualys, wvu, including Metasploit module exploits/unix/local/opensmtpd_oob_read_lpe.
AI-analyzed exploit summary This Metasploit module exploits CVE-2020-8794, an out-of-bounds read vulnerability in OpenSMTPD, to achieve local privilege escalation. It leverages a malformed SMTP message to execute arbitrary commands as root or nobody, depending on the OpenSMTPD grammar version.
Description
OpenSMTPD before 6.6.4 allows remote code execution because of an out-of-bounds read in mta_io in mta_session.c for multi-line replies. Although this vulnerability affects the client side of OpenSMTPD, it is possible to attack a server because the server code launches the client code during bounce handling.
Exploits (3)
This Metasploit module exploits CVE-2020-8794, an out-of-bounds read vulnerability in OpenSMTPD, to achieve local privilege escalation. It leverages a malformed SMTP message to execute arbitrary commands as root or nobody, depending on the OpenSMTPD grammar version.
This exploit demonstrates a local privilege escalation (LPE) and remote code execution (RCE) vulnerability in OpenSMTPD's default installation. It leverages a flaw in the SMTP server's grammar parsing to inject arbitrary commands, allowing an attacker to execute code as the root user.
This Metasploit module exploits CVE-2020-8794, an out-of-bounds read vulnerability in OpenSMTPD, to achieve local privilege escalation by sending a malformed SMTP message to execute arbitrary commands as root or nobody, depending on the grammar version.
References (11)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H