CVE-2016-6662
59Vexday Risk Score
Prioritize patching. It exploitation observed by VulnCheck, has a public proof of concept and 48 threat group(s) use it.
ssvc Actepss 60%
from disclosure to weapon0 days
Published on NVDSep 20
1st PoCSep 12
VulnCheck+2793d
exploitation probability
60%top 1% of all CVEs
observed exploitation
yesVulnCheck
48 group(s)11 public exploit(s)
Who exploits it — 48
Groups known to exploit this vulnerability (MITRE ATT&CK attribution).
APT / StateAgrius🇮🇷 MITRE ATT&CK
APT / StateAPT28🇷🇺 MITRE ATT&CK
APT / StateAPT29🇷🇺 MITRE ATT&CK
APT / StateAPT39🇮🇷 MITRE ATT&CK
APT / StateAPT41🇨🇳 MITRE ATT&CK
APT / StateAPT5🇨🇳 MITRE ATT&CK
APT / StateAxiom🇨🇳 MITRE ATT&CK
APT / StateBackdoorDiplomacy MITRE ATT&CK
APT / StateBlackByte MITRE ATT&CK
APT / StateBlackTech🇨🇳 MITRE ATT&CK
APT / StateBlue Mockingbird MITRE ATT&CK
APT / StateCinnamon Tempest🇨🇳 MITRE ATT&CK
APT / StateDragonfly🇷🇺 MITRE ATT&CK
APT / StateEarth Lusca🇨🇳 MITRE ATT&CK
APT / StateEmber Bear🇷🇺 MITRE ATT&CK
APT / StateFIN13 MITRE ATT&CK
APT / StateFIN7 MITRE ATT&CK
APT / StateFox Kitten🇮🇷 MITRE ATT&CK
APT / StateGALLIUM🇨🇳 MITRE ATT&CK
APT / StateGOLD SOUTHFIELD MITRE ATT&CK
APT / StateHAFNIUM🇨🇳 MITRE ATT&CK
APT / StateINC Ransom MITRE ATT&CK
APT / StateKe3chang🇨🇳 MITRE ATT&CK
APT / StateKimsuky🇰🇵 MITRE ATT&CK
APT / StateLeviathan🇨🇳 MITRE ATT&CK
APT / StateMagic Hound🇮🇷 MITRE ATT&CK
APT / StateMedusa Group MITRE ATT&CK
APT / StatemenuPass🇨🇳 MITRE ATT&CK
APT / StateMirrorFace🇨🇳 MITRE ATT&CK
APT / StateMoses Staff🇮🇷 MITRE ATT&CK
APT / StateMuddyWater🇮🇷 MITRE ATT&CK
APT / StatePlay MITRE ATT&CK
APT / StateRocke🇨🇳 MITRE ATT&CK
APT / StateSalt Typhoon🇨🇳 MITRE ATT&CK
APT / StateSandworm Team🇷🇺 MITRE ATT&CK
APT / StateSea Turtle MITRE ATT&CK
APT / StateShinyHunters MITRE ATT&CK
APT / StateStorm-0501 MITRE ATT&CK
APT / StateTeamPCP MITRE ATT&CK
APT / StateThreat Group-3390🇨🇳 MITRE ATT&CK
APT / StateToddyCat MITRE ATT&CK
APT / StateTonto Team🇨🇳 MITRE ATT&CK
APT / StateUNC3886🇨🇳 MITRE ATT&CK
APT / StateVOID MANTICORE🇮🇷 MITRE ATT&CK
APT / StateVolatile Cedar MITRE ATT&CK
APT / StateVolt Typhoon🇨🇳 MITRE ATT&CK
APT / StateWinter Vivern🇷🇺 MITRE ATT&CK
APT / StateWizard Spider🇷🇺 MITRE ATT&CK
Oracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x through 5.7.15; MariaDB before 5.5.51, 10.0.x before 10.0.27, and 10.1.x before 10.1.17; and Percona Server before 5.5.51-38.1, 5.6.x before 5.6.32-78.0, and 5.7.x before 5.7.14-7 allow local users to create arbitrary configurations and bypass certain protection mechanisms by setting general_log_file to a my.cnf configuration. NOTE: this can be leveraged to execute arbitrary code with root privileges by setting malloc_lib. NOTE: the affected MySQL version information is from Oracle's October 2016 CPU. Oracle has not commented on third-party claims that the issue was silently patched in MySQL 5.5.52, 5.6.33, and 5.7.15.
Affected products
n/a · n/apublic PoCs found — 11
exploitdbwww.exploit-db.com/exploits/40360unverifiedgithubgithub.com/MAYASEVEN/CVE-2016-6662★ 29githubgithub.com/Ashrafdev/MySQL-Remote-Root-Code-Execution★ 9githubgithub.com/boompig/cve-2016-6662★ 1githubgithub.com/meersjo/ansible-mysql-cve-2016-6662★ 1githubgithub.com/konstantin-kelemen/mysqld_safe-CVE-2016-6662-patch★ 0githubgithub.com/KosukeShimofuji/CVE-2016-6662★ 0vulncheckvulncheck.com/xdb/60add9bf4d4eunverifiedcve_referencewww.exploit-db.com/exploits/40360/unverifiedvulncheckvulncheck.com/xdb/77badbece00eunverifiedvulncheckvulncheck.com/xdb/39e334b00224unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://legalhackers.com/advisories/MySQL-Exploit-Remote-Root-Code-Execution-Privesc-CVE-2016-6662.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2058.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2059.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2060.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2061.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2062.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2077.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2130.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2131.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2595.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2749.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2927.html