EIP-2026-114689
PRE-CVEQNX 6.5.0 x86 phfont - Local Privilege Escalation
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-114689. PoCs published by cenobyte.
AI-analyzed exploit summary This is a functional local privilege escalation exploit for QNX 6.5.0 targeting a buffer overflow in the setuid-root binary /usr/photon/bin/phfont via the PHOTON_PATH environment variable. It uses a return-to-libc technique to execute system() with a crafted payload, ultimately spawning a root shell.
Description
QNX 6.5.0 x86 phfont - Local Privilege Escalation
Exploits (1)
This is a functional local privilege escalation exploit for QNX 6.5.0 targeting a buffer overflow in the setuid-root binary /usr/photon/bin/phfont via the PHOTON_PATH environment variable. It uses a return-to-libc technique to execute system() with a crafted payload, ultimately spawning a root shell.