vendor:
MySQL
by:
ninpwn
7.5
CVSS
HIGH
Local Privilege Escalation
CWE
Product Name: MySQL
Affected Version From: MySQL 4.x
Affected Version To: MySQL 5.x
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Debian GNU/Linux 9
2021
MySQL User-Defined (Linux) x32 / x86_64 – ‘sys_exec’ Local Privilege Escalation (2)
This exploit targets a vulnerability in MySQL User-Defined (Linux) x32 / x86_64. It allows an attacker to escalate their privileges locally by executing malicious code through the 'sys_exec' function.
Mitigation:
To mitigate this vulnerability, it is recommended to apply the latest security patches and updates for MySQL. Additionally, access controls should be implemented to limit the privileges of database users.