vendor:
PlayStation 4
by:
qwertyoruiopz, Flatz, Vortex, OpenOrbis Team, Anonymous
9.8
CVSS
HIGH
Kernel Exploit
N/A
CWE
Product Name: PlayStation 4
Affected Version From: 5.05
Affected Version To: 5.05
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: PlayStation 4
2018
PS4 5.05 Kernel Exploit
This project contains a full implementation of the second 'bpf' kernel exploit for the PlayStation 4 on 5.05. It will allow you to run arbitrary code as kernel, to allow jailbreaking and kernel-level modifications to the system. This exploit also contains autolaunching code for Mira and Vortex's HEN payload. The bug was discovered by qwertyoruiopz and the patches included are Disable kernel write protection, Allow RWX (read-write-execute) memory mapping, Syscall instruction allowed anywhere, Dynamic Resolving (`sys_dynlib_dlsym`) allowed from any process, Custom system call #11 (`kexec()`) to execute arbitrary code in kernel mode and Allow unprivileged users to call `setuid(0)` successfully.
Mitigation:
N/A