vendor:
AIX
by:
@hxmonsegur
7,2
CVSS
HIGH
Privilege Escalation
264
CWE
Product Name: AIX
Affected Version From: AIX 6.1
Affected Version To: AIX 7.2.0.2
Patch Exists: YES
Related CWE: N/A
CPE: aix:6.1:7.2.0.2
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: AIX
2016
AIX lsmcode local root exploit
This exploit is used to gain root access on AIX 6.1/7.1/7.2.0.2 systems. It takes advantage of a vulnerability in the lsmcode binary, which allows an attacker to create a SUID root shell. The exploit sets environment variables, sets the umask to 000, executes the vulnerable binary, and then creates a SUID root shell. The exploit then cleans up the environment variables and executes the ibstat binary to gain root access.
Mitigation:
The best way to mitigate this vulnerability is to patch the system with the latest security updates.