Apple iOS 11.2.5 / watchOS 4.2.2 / tvOS 11.2.5 bluetoothd Memory Corruption

Facebooktwittergoogle_plusredditpinterestlinkedinmail

Apple iOS version 11.2.5, watchOS version 4.2.2, and tvOS version 11.2.5 bluetoothd memory corruption proof of concept exploit.

Powered by WPeMatico

Facebooktwittergoogle_plusredditpinterestlinkedinmail

MagniComp SysInfo mcsiwrapper Privilege Escalation

Facebooktwittergoogle_plusredditpinterestlinkedinmail

This Metasploit module attempts to gain root privileges on systems running MagniComp SysInfo versions prior to 10-H64. The .mcsiwrapper suid executable allows loading a config file using the ‘–configfile’ argument. The ‘ExecPath’ config directive is used to set the executable load path. This Metasploit module abuses this functionality to set the load path resulting in execution of arbitrary code as root. This Metasploit module has been tested successfully with SysInfo version 10-H63 on Fedora 20 x86_64, 10-H32 on Fedora 27 x86_64, 10-H10 on Debian 8 x86_64, and 10-GA on Solaris 10u11 x86.

Powered by WPeMatico

Facebooktwittergoogle_plusredditpinterestlinkedinmail