EIP-2026-102868
PRE-CVEHP System Management Homepage - Local Privilege Escalation (Metasploit)
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-102868. PoCs published by Metasploit.
AI-analyzed exploit summary This Metasploit module exploits a local buffer overflow in HP System Management Homepage's setuid binary `smhstart` via the `SSL_SHARE_BASE_DIR` environment variable. It achieves privilege escalation by overwriting the return address with a `call esp` gadget and executing shellcode.
Description
HP System Management Homepage - Local Privilege Escalation (Metasploit)
Exploits (1)
This Metasploit module exploits a local buffer overflow in HP System Management Homepage's setuid binary `smhstart` via the `SSL_SHARE_BASE_DIR` environment variable. It achieves privilege escalation by overwriting the return address with a `call esp` gadget and executing shellcode.