Description
Utilizing Rancher Server, an attacker can create a docker container with the '/' path mounted with read/write permissions on the host server that is running the docker container. As the docker container executes command as uid 0 it is honored by the host operating system allowing the attacker to edit/create files owed by root. This exploit abuses this to creates a cron job in the '/etc/cron.d/' path of the host server.
The Docker image should exist on the target system or be a valid image from hub.docker.com.
Use `check` with verbose mode to get a list of exploitable Rancher Hosts managed by the target system.
Module options
To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':
msf > use exploit/linux/http/rancher/servermsf undefined(server) > show actions ...actions...msf undefined(server) > set ACTION < action-name >msf undefined(server) > show options ...show and set options...msf undefined(server) > runPrioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub