EIP-2026-118393
PRE-CVECuckoo Sandbox Guest 2.0.1 - XMLRPC Privileged Remote Code Execution
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-118393. PoCs published by Rémi ROCHER.
AI-analyzed exploit summary This exploit leverages the Cuckoo Sandbox Guest XMLRPC interface to achieve privileged remote code execution by uploading a malicious ZIP file containing a Python script that spawns a process (e.g., calc.exe) with Administrator privileges. It assumes the Cuckoo agent is running with elevated privileges and the attacker has access to the XMLRPC port.
Description
Cuckoo Sandbox Guest 2.0.1 - XMLRPC Privileged Remote Code Execution
Exploits (1)
This exploit leverages the Cuckoo Sandbox Guest XMLRPC interface to achieve privileged remote code execution by uploading a malicious ZIP file containing a Python script that spawns a process (e.g., calc.exe) with Administrator privileges. It assumes the Cuckoo agent is running with elevated privileges and the attacker has access to the XMLRPC port.