vendor:
Enlightenment
by:
spender
7.2
CVSS
HIGH
Privilege Escalation
20
CWE
Product Name: Enlightenment
Affected Version From: 0.16.8.1
Affected Version To: 0.16.999.056
Patch Exists: YES
Related CWE: CVE-2009-3093
CPE: a:enlightenment:enlightenment
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux
2009
Enlightenment
This exploit is a proof-of-concept for a privilege escalation vulnerability in the Enlightenment window manager. It allows a local user to gain root privileges. The vulnerability is due to a lack of proper input validation in the Enlightenment window manager. The exploit works by creating a specially crafted X11 window, which can be used to overwrite a function pointer in the Enlightenment window manager. This allows the attacker to execute arbitrary code with root privileges.
Mitigation:
The vendor has released a patch to address this vulnerability.