vendor:
RedStar 3.0
by:
HackerFantastic
7.8
CVSS
HIGH
Privilege Escalation
264
CWE
Product Name: RedStar 3.0
Affected Version From: RedStar 3.0
Affected Version To: RedStar 3.0
Patch Exists: No
Related CWE: N/A
CPE: o:redstar:redstar_3.0
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux
2015
RedStar 3.0 Local Root Exploit
This exploit is used to gain root access on RedStar 3.0 systems. It involves creating a malicious udev rule which will execute a shell script that adds a new entry to the sudoers file. This allows the user to gain root access without a password.
Mitigation:
The user should ensure that the udev rules are not modified and that the sudoers file is not modified without authorization.