vendor:
AIX
by:
hxmonsegur
7,2
CVSS
HIGH
Privilege Escalation
264
CWE
Product Name: AIX
Affected Version From: AIX 5.3
Affected Version To: AIX 7.2
Patch Exists: YES
Related CWE: CVE-2009-1786, CVE-2009-2669, CVE-2014-3074
CPE: aix:lquerylv
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: AIX
2016
AIX lquerylv 5.3, 6.1, 7.1, 7.2 local root exploit
This exploit takes advantage of known issues with debugging functions within the AIX linker library. We are taking advantage of known functionality, and focusing on badly coded SUID binaries which do not adhere to proper security checks prior to seteuid/open/writes. The CVEs we will be taking advantage of are CVE-2009-1786, CVE-2009-2669, and CVE-2014-3074. In each instance of the aforementioned CVEs, IBM merely patched the binaries which were reported in the original reports as being used for escalation of the vulnerabilities. This allowed for the lquerylv binary to slip by their patches and become an attack vector.
Mitigation:
Apply the latest patches from IBM for AIX 5.3, 6.1, 7.1, and 7.2.