Privilege escalation in ServerProtect for Linux - CVE-2017-9036

 

Privilege escalation in ServerProtect for Linux - CVE-2017-9036

Published: May 25, 2017


Vulnerability identifier: #VU6721
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-9036
CWE-ID: CWE-264
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The disclosed vulnerability allows a local attacker to gain elevated privileges on the target system.

The vulnerability exists due to improper security restrictions set on the quarantine directory by the affected software. A local attacker can write an arbitrary file to any location on the file system and gain root privileges.

Successful exploitation of this vulnerability results in privilege escalation.



Affected software

ServerProtect for Linux

How to mitigate CVE-2017-9036

Update to version 3.0 CP 1531.



External References

Related Security Bulletins