CVE-2017-6516
HIGH 7.2EPSS 5.3%
A Local Privilege Escalation Vulnerability in MagniComp's Sysinfo before 10-H64 for Linux and UNIX platforms could allow a local attacker to gain elevated privileges. Parts of SysInfo require setuid-to-root access in order to access restricted system files and make restricted kernel calls. This access could be exploited by a local attacker to gain a root shell prompt using the right combination of environment variables and command line arguments.
- CVSS v3.0
- 6.7 MEDIUM
CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H - CVSS v2.0
- 7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C - EPSS
- 5.29% chance of exploitation in the next 30 days, 92th percentile
- Published
- 2017-03-14
- Updated
- 2024-08-05
Proof-of-concept exploits (1)
- Rubytox/CVE-2017-6516-mcsiwrapper-0★ · 2022-05-27