ID:5205 - Exploit for Permissions, Privileges, and Access Controls in OpenSMTPD - CVE-2020-8793
Published: March 12, 2021
OpenSMTPD
Link to public exploit:
Vulnerability description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to the application does not drop privileges when executing the "/usr/sbin/smtpctl" application with a "-bi" command-line argument. A local user can leverage this behavior and use a specially crafted hardlink to execute arbitrary code on the system with elevated privileges.