ID:1209 - Exploit for Improper input validation in smb4k - CVE-2017-8849

 
Main Vulnerability Database Exploits ID:1209 - Exploit for Improper input validation in smb4k - CVE-2017-8849

ID:1209 - Exploit for Improper input validation in smb4k - CVE-2017-8849

Published: March 18, 2020


Vulnerability identifier: #VU6661
Vulnerability risk: Low
CVE-ID: CVE-2017-8849
CWE-ID: CWE-20
Exploitation vector: Local access
Vulnerable software:
smb4k

Link to public exploit:


Vulnerability description

The vulnerability allows a local user to elevate privileges.

The vulnerability exists due to an input validation error when verify arguments, sent to the mount helper DBUS service.A local user can send a specially crafted request and execute arbitrary code on the system with root privileges.

Remediation

Update to version 2.0.1.