Description
This exploit targets the Linux kernel bug in OverlayFS.
A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities was found in the Linux kernel's OverlayFS subsystem in how a user copies a capable file from a nosuid mount into another mount. This uid mapping bug allows a local user to escalate their privileges on the system.
Module options
To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':
msf > use exploit/linux/local/cve_2023_0386_overlayfs_priv_escmsf undefined(cve_2023_0386_overlayfs_priv_esc) > show actions ...actions...msf undefined(cve_2023_0386_overlayfs_priv_esc) > set ACTION < action-name >msf undefined(cve_2023_0386_overlayfs_priv_esc) > show options ...show and set options...msf undefined(cve_2023_0386_overlayfs_priv_esc) > runPrioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub