vendor:
Centrify Deployment Manager
by:
larry
8,8
CVSS
HIGH
Race Condition
362
CWE
Product Name: Centrify Deployment Manager
Affected Version From: 2.1.0.283
Affected Version To: 2.1.0.283
Patch Exists: YES
Related CWE: N/A
CPE: a:centrify:centrify_deployment_manager
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux
2012
Centrify Deployment Manager v2.1.0.283 local root
A race condition vulnerability was discovered in Centrify Deployment Manager v2.1.0.283, which allowed an attacker to gain root access by creating a symbolic link to /etc/shadow and then executing a malicious command before the software had a chance to execute its own command.
Mitigation:
The vendor has released a patch to address this vulnerability.