vendor:
LXD Alpine Builder
by:
Marcelo Vazquez and Victor Lasa
8.8
CVSS
HIGH
Privilege Escalation
269
CWE
Product Name: LXD Alpine Builder
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Linux
2020
LXD Alpine Builder Privilege Escalation
This exploit is a privilege escalation vulnerability in LXD Alpine Builder. It allows an attacker to gain root access to the victim machine by running a malicious script. The attacker first downloads the build-alpine script from the GitHub repository and runs it as root user. Then, the attacker creates a container using the malicious script and adds a device to the container with the source set to the root directory of the victim machine. Finally, the attacker executes the script and gains root access to the victim machine.
Mitigation:
The best way to mitigate this vulnerability is to restrict access to the root directory of the victim machine. Additionally, users should ensure that they are running the latest version of LXD Alpine Builder and that all security patches are applied.