ID:4891 - Exploit for Permissions, Privileges, and Access Controls in OpenSMTPD - CVE-2020-8793
Published: November 30, 2020
OpenSMTPD
Link to public exploit:
Vulnerability description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to the application does not drop privileges when executing the "/usr/sbin/smtpctl" application with a "-bi" command-line argument. A local user can leverage this behavior and use a specially crafted hardlink to execute arbitrary code on the system with elevated privileges.