header-logo
Suggest Exploit
vendor:
by:
Michal Zalewski
7.5
CVSS
HIGH
Privilege Escalation
CWE
Product Name:
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Metasploit:
Other Scripts:
Platforms Tested:

Vixie-cron Root Exploit

This exploit targets systems running vixie cron and requires root or another chosen user to execute the 'crontab -e' or 'crontab /any/file' command. It spoofs the legitimate cron entry file with malicious content, leading to account compromise, usually resulting in root compromise.

Mitigation:

Update vixie cron to a non-vulnerable version.
Source

Exploit-DB raw data: