CVE-2015-5287
9.5 CISA KEVRed Hat · Automatic Bug Reporting Tool (ABRT)
The ABRT tool contains a local privilege escalation vulnerability via symlink attacks on predictable file names in /var/tmp or /var/spool, allowing authenticated local users to gain root privileges.
Executive summary
A critical local privilege escalation vulnerability in Red Hat Automatic Bug Reporting Tool is being actively exploited in the wild, posing an immediate risk of full system compromise.
Vulnerability
The vulnerability exists in the abrt-hook-ccpp help program, which is susceptible to a symlink attack. An authenticated local user can manipulate file paths during the coredump process to overwrite system files or execute arbitrary code with root privileges.
Business impact
Successful exploitation of this vulnerability grants a local attacker full root-level control over the affected system. This leads to complete loss of confidentiality, integrity, and availability. Given the CVSS score of 9.5 and the confirmation of active exploitation in the CISA Known Exploited Vulnerabilities (KEV) catalog, this vulnerability represents an extreme risk to organizational security and requires immediate remediation.
Remediation
Immediate Action: Update the Automatic Bug Reporting Tool (ABRT) to version 2.7.1 or later immediately. Refer to the Red Hat Security Advisory RHSA-2015-2505 for specific package update instructions.
Proactive Monitoring: Monitor system logs and audit trails for unauthorized attempts to access or modify files within the /var/tmp/abrt and /var/spool/abrt directories. Alert on any unexpected execution of scripts or binaries originating from temporary directories.
Compensating Controls: If immediate patching is not feasible, restrict local access to the system to only trusted users. Additionally, implement strict file system permissions and monitor for the creation of unexpected symlinks in sensitive spool or temporary directories.
Exploitation status
Public Exploit Available: Yes, a functional exploit script is available via ExploitDB (EDB-ID 38832).
Analyst recommendation
Due to the severity of this vulnerability and the confirmed active exploitation documented in the CISA KEV catalog, all organizations running vulnerable versions of the Red Hat Automatic Bug Reporting Tool must prioritize patching. Failure to address this flaw leaves systems exposed to trivial local root escalation. Apply the vendor-provided updates immediately to mitigate this critical risk.
More Red Hat CVEs
Sources
- RHSA-2015:2505 Vendor advisory
- 38832 Exploit / PoC
- [oss-security] 20151201 CVE-2015-5273 + CVE-2015-5287, abrt local root in Centos/Fedora/RHEL Mailing list
- oracle.com
- bugzilla.redhat.com
- 78137 Vulnerability database entry
- github.com
- packetstormsecurity.com