Exploitation Summary
EIP tracks 1 public exploit for CVE-2024-36587. PoCs published by meeeeing.
AI-analyzed exploit summary This repository demonstrates a local privilege escalation (LPE) vulnerability in dnscrypt-proxy (CVE-2024-36587) via binary planting. The Dockerfile sets up an environment where a malicious 'id' binary is planted and executed during service installation, proving the exploit.
Description
Insecure permissions in DNSCrypt-proxy v2.0.0alpha9 to v2.1.5 allows non-privileged attackers to escalate privileges to root via overwriting the binary dnscrypt-proxy.
Exploits (1)
This repository demonstrates a local privilege escalation (LPE) vulnerability in dnscrypt-proxy (CVE-2024-36587) via binary planting. The Dockerfile sets up an environment where a malicious 'id' binary is planted and executed during service installation, proving the exploit.
References (1)
Scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H