Описание
SolarWinds Virtualization Manager 6.3.1 and earlier allow local users to gain privileges by leveraging a misconfiguration of sudo, as demonstrated by "sudo cat /etc/passwd."
SolarWinds Virtualization Manager 6.3.1 and earlier allow local users to gain privileges by leveraging a misconfiguration of sudo, as demonstrated by "sudo cat /etc/passwd."
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2016-3643
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-3643
- https://www.exploit-db.com/exploits/39967
- http://packetstormsecurity.com/files/137487/Solarwinds-Virtualization-Manager-6.3.1-Privilege-Escalation.html
- http://seclists.org/fulldisclosure/2016/Jun/26
Связанные уязвимости
CVSS3: 7.8
nvd
больше 9 лет назад
SolarWinds Virtualization Manager 6.3.1 and earlier allow local users to gain privileges by leveraging a misconfiguration of sudo, as demonstrated by "sudo cat /etc/passwd."
fstec
больше 9 лет назад
Уязвимость программного средства виртуализации SolarWinds Virtualization Manager, позволяющая нарушителю повысить свои привилегии