#VU25586 Permissions, Privileges, and Access Controls in OpenSMTPD - CVE-2020-8793
Published: February 25, 2020 / Updated: September 23, 2021
OpenSMTPD
OpenBSD
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to the application does not drop privileges when executing the "/usr/sbin/smtpctl" application with a "-bi" command-line argument. A local user can leverage this behavior and use a specially crafted hardlink to execute arbitrary code on the system with elevated privileges.