Description
This module attempts to gain root privileges on Linux systems using setuid executables compiled with AddressSanitizer (ASan).
ASan configuration related environment variables are permitted when executing setuid executables built with libasan. The `log_path` option can be set using the `ASAN_OPTIONS` environment variable, allowing clobbering of arbitrary files, with the privileges of the setuid user.
This module uploads a shared object and sprays symlinks to overwrite `/etc/ld.so.preload` in order to create a setuid root shell.
Module options
To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':
msf > use exploit/linux/local/asan/suid_executable_priv_escmsf undefined(suid_executable_priv_esc) > show actions ...actions...msf undefined(suid_executable_priv_esc) > set ACTION < action-name >msf undefined(suid_executable_priv_esc) > show options ...show and set options...msf undefined(suid_executable_priv_esc) > runPrioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub