Description
This module exploits a directory traversal vulnerability in the `dtappgather` executable included with Common Desktop Environment (CDE) on unpatched Solaris systems prior to Solaris 10u11 which allows users to gain root privileges.
dtappgather allows users to create a user-owned directory at any location on the filesystem using the `DTUSERSESSION` environment variable.
This module creates a directory in `/usr/lib/locale`, writes a shared object to the directory, and runs the specified SUID binary with the shared object loaded using the `LC_TIME` environment variable.
This module has been tested successfully on:
Solaris 9u7 (09/04) (x86); Solaris 10u1 (01/06) (x86); Solaris 10u2 (06/06) (x86); Solaris 10u4 (08/07) (x86); Solaris 10u8 (10/09) (x86); Solaris 10u9 (09/10) (x86).
Module options
To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':
msf > use exploit/solaris/local/extremeparr/dtappgather_priv_escmsf undefined(dtappgather_priv_esc) > show actions ...actions...msf undefined(dtappgather_priv_esc) > set ACTION < action-name >msf undefined(dtappgather_priv_esc) > show options ...show and set options...msf undefined(dtappgather_priv_esc) > runPrioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub