Exploitation Summary
EIP tracks 1 public exploit for CVE-2021-27285. PoCs published by fjh1997.
AI-analyzed exploit summary This PoC demonstrates a local privilege escalation (LPE) vulnerability in Inspur ClusterEngine v4.0 due to improper SUID configuration on the binary '/opt/tsce4/torque6/bin/getJobsByShell'. Non-administrative users can exploit this to gain root access by executing the binary with '/bin/sh' as an argument.
Description
An issue was discovered in Inspur ClusterEngine v4.0 that allows attackers to gain escalated Local privileges and execute arbitrary commands via /opt/tsce4/torque6/bin/getJobsByShell.
Exploits (1)
This PoC demonstrates a local privilege escalation (LPE) vulnerability in Inspur ClusterEngine v4.0 due to improper SUID configuration on the binary '/opt/tsce4/torque6/bin/getJobsByShell'. Non-administrative users can exploit this to gain root access by executing the binary with '/bin/sh' as an argument.
References (1)
Scores
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H