vendor:
AIX
by:
watercloud@xfocus.org
7.2
CVSS
HIGH
Privilege Escalation
264
CWE
Product Name: AIX
Affected Version From: AIX 4.x
Affected Version To: AIX 5L
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: AIX 4.x, AIX 5L
2003
Exploit diagrpt of Aix4.x & 5L to get a uid=0 shell
AIX ships with a diagnostic reporting utility called 'diagrpt'. This utility is installed setuid root by default. When 'diagrpt' executes, it relies on an environment variable to locate another utility which it executes. This utility is executed by 'diagrpt' as root. An attacker can gain root privileges by having 'diagrpt' execute a malicious program of the same name in a directory under their control.
Mitigation:
Restrict access to the diagrpt utility and ensure that it is not setuid root.