EIP-2026-102967
PRE-CVERealOne Player for Linux 2.2 Alpha - Insecure Configuration File Permission Privilege Escalation
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-102967. PoCs published by Jon Hart.
AI-analyzed exploit summary This exploit leverages insecure group-writable permissions on RealOne Player 9 configuration files to replace a shared library (cook.so.6.0) with a malicious version. When the victim runs RealPlayer, it executes the trojaned library, which binds a shell to port 12345, allowing privilege escalation to the victim's user context.
Description
RealOne Player for Linux 2.2 Alpha - Insecure Configuration File Permission Privilege Escalation
Exploits (1)
This exploit leverages insecure group-writable permissions on RealOne Player 9 configuration files to replace a shared library (cook.so.6.0) with a malicious version. When the victim runs RealPlayer, it executes the trojaned library, which binds a shell to port 12345, allowing privilege escalation to the victim's user context.