Description
This module exploits a command injection vulnerability in IBM AIX invscout set-uid root utility present in AIX 7.2 and earlier.
The undocumented -rpm argument can be used to install an RPM file; and the undocumented -o argument passes arguments to the rpm utility without validation, leading to command injection with effective-uid root privileges.
This module has been tested successfully on AIX 7.2.
Module options
To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':
msf > use exploit/aix/local/invscout/rpm_priv_escmsf undefined(rpm_priv_esc) > show actions ...actions...msf undefined(rpm_priv_esc) > set ACTION < action-name >msf undefined(rpm_priv_esc) > show options ...show and set options...msf undefined(rpm_priv_esc) > runPrioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub