CVE-2023-2640
HIGH EXPLOITED NUCLEIGameOver(lay) Privilege Escalation and Container Escape
Title source: metasploitExploitation Summary
CVE-2023-2640 has been observed exploited in the wild (reported by VulnCheck KEV).
EIP tracks 15 public exploits from researchers including g1vi, luanoliveira350, OllaPapito, including a Metasploit module exploits/linux/local/gameoverlay_privesc.
A Nuclei detection template is also available.
AI-analyzed exploit summary The repository contains a functional exploit script for CVE-2023-2640 and CVE-2023-32629, which are privilege escalation vulnerabilities in Ubuntu kernels due to improper permission checks in overlayfs. The exploit leverages overlayfs to set privileged extended attributes and gain root access.
Description
On Ubuntu kernels carrying both c914c0e27eb0 and "UBUNTU: SAUCE: overlayfs: Skip permission checking for trusted.overlayfs.* xattrs", an unprivileged user may set privileged extended attributes on the mounted files, leading them to be set on the upper files without the appropriate security checks.
Exploits (15)
The repository contains a functional exploit script for CVE-2023-2640 and CVE-2023-32629, which are privilege escalation vulnerabilities in Ubuntu kernels due to improper permission checks in overlayfs. The exploit leverages overlayfs to set privileged extended attributes and gain root access.
The repository contains a functional exploit script for CVE-2023-2640 and CVE-2023-32629, targeting a vulnerability in OverlayFS on Ubuntu 20.04 with kernel 5.4.0. The script leverages unshare, setcap, and overlay mounting to escalate privileges and execute commands as root.
This repository contains a functional local privilege escalation (LPE) exploit for CVE-2023-2640, targeting Ubuntu systems with specific kernel versions. The exploit leverages overlayfs and capability manipulation to escalate privileges to root.
The repository contains a functional privilege escalation exploit for CVE-2023-2640 and CVE-2023-32629, leveraging overlayfs and capability manipulation to gain root access. The script automates the exploitation process by creating directories, copying Python, setting capabilities, and mounting an overlay filesystem.
The repository contains a functional privilege escalation exploit for CVE-2023-2640 and CVE-2023-32629, leveraging overlayfs and setcap to gain root access on vulnerable Ubuntu kernels. The PoC script automates the exploitation process by creating a namespace, mounting an overlay filesystem, and executing a Python payload to escalate privileges.
The repository contains functional exploit scripts for CVE-2023-2640 and CVE-2023-32629, leveraging overlayfs and capability manipulation to achieve local privilege escalation on Ubuntu systems. The scripts use unshare, setcap, and overlayfs mounting to gain root access.
The repository contains a functional exploit script (`exp.sh`) that leverages CVE-2023-2640 and CVE-2023-32629 to achieve local privilege escalation (LPE) on vulnerable Ubuntu kernels (6.2.0, 5.19.0, 5.4.0) by abusing overlayfs permission checks to set privileged extended attributes and escalate to root.
This repository contains a functional exploit for CVE-2023-2640 and CVE-2023-32629, which are Ubuntu Kernel OverlayFS vulnerabilities allowing local privilege escalation. The exploit leverages the `ovl_copy_up` flaw to leak high-privilege capabilities and execute a true root shell outside the user namespace sandbox.
This repository contains functional exploit scripts for CVE-2023-2640 and CVE-2023-3262, which are OverlayFS local privilege escalation vulnerabilities in Ubuntu. The scripts demonstrate the exploitation of permission handling and capability escalation issues to achieve root access.
This PoC demonstrates CVE-2023-2640, an OverlayFS permission issue, by creating a directory structure and mounting an overlay filesystem to exploit incorrect permission handling. The script uses unshare and mount commands to trigger the vulnerability.
This repository contains a functional exploit for CVE-2018-12613 (phpMyAdmin RCE) and CVE-2023-2640 (GameOver(lay) privilege escalation). It includes Python-based RCE exploit, reverse shell scripts, and kernel exploit for privilege escalation.
This Metasploit module exploits CVE-2023-2640, a privilege escalation vulnerability in Ubuntu kernels due to unsafe overlayfs operations. It leverages the vulnerability to gain root access by manipulating file capabilities in a union-mounted directory.
The repository contains only a README with minimal information, no exploit code, and references two CVEs without technical details. It appears to be a placeholder or lure.
This script exploits a local privilege escalation vulnerability by leveraging overlayfs and capability manipulation to gain root access. It uses unshare, setcap, and overlayfs mounting to bypass restrictions and execute a shell with elevated privileges.
The repository contains a functional privilege escalation exploit for CVE-2023-32629 and CVE-2023-2640, leveraging overlayfs and capability manipulation to gain root access on vulnerable Ubuntu systems. The exploit is a bash one-liner that automates the process.
Nuclei Templates (1)
cpe:"cpe:2.3:o:canonical:ubuntu_linux"
References (4)
Scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H