vendor:
MySQL
by:
d7x
7.5
CVSS
HIGH
Local Privilege Escalation
264
CWE
Product Name: MySQL
Affected Version From: MySQL 4.x
Affected Version To: MySQL 5.x
Patch Exists: NO
Related CWE:
CPE: mysql
Platforms Tested: Debian GNU/Linux 8.11
2019
MySQL User-Defined (Linux) x32 / x86_64 sys_exec function local privilege escalation exploit
This exploit takes advantage of a vulnerability in MySQL 4.x/5.x on Linux systems to escalate privileges locally. It uses a user-defined function (UDF) to execute arbitrary shellcode. The exploit is based on the raptor_udf.c exploit by Marco Ivaldi.
Mitigation:
Patch/update to a non-vulnerable version of MySQL.