CVE-2016-6662
59Vexday Risk Score
Prioritize patching. It exploitation observed by VulnCheck, has a public proof of concept and 48 threat group(s) use it.
ssvc Actepss 68%
from disclosure to weapon0 days
Published on NVDSep 20
1st PoCSep 12
VulnCheck+2793d
exploitation probability
68%top 1% of all CVEs
observed exploitation
yesVulnCheck
48 group(s)11 public exploit(s)
Who exploits it — 48
Groups known to exploit this vulnerability (MITRE ATT&CK attribution).
APT / StateAgrius🇮🇷APT / StateAPT28🇷🇺APT / StateAPT29🇷🇺APT / StateAPT39🇮🇷APT / StateAPT41🇨🇳APT / StateAPT5🇨🇳APT / StateAxiom🇨🇳APT / StateBackdoorDiplomacyAPT / StateBlackByteAPT / StateBlackTech🇨🇳APT / StateBlue MockingbirdAPT / StateCinnamon Tempest🇨🇳APT / StateDragonfly🇷🇺APT / StateEarth Lusca🇨🇳APT / StateEmber Bear🇷🇺APT / StateFIN13APT / StateFIN7APT / StateFox Kitten🇮🇷APT / StateGALLIUM🇨🇳APT / StateGOLD SOUTHFIELDAPT / StateHAFNIUM🇨🇳APT / StateINC RansomAPT / StateKe3chang🇨🇳APT / StateKimsuky🇰🇵APT / StateLeviathan🇨🇳APT / StateMagic Hound🇮🇷APT / StateMedusa GroupAPT / StatemenuPass🇨🇳APT / StateMirrorFace🇨🇳APT / StateMoses Staff🇮🇷APT / StateMuddyWater🇮🇷APT / StatePlayAPT / StateRocke🇨🇳APT / StateSalt Typhoon🇨🇳APT / StateSandworm Team🇷🇺APT / StateSea TurtleAPT / StateShinyHuntersAPT / StateStorm-0501APT / StateTeamPCPAPT / StateThreat Group-3390🇨🇳APT / StateToddyCatAPT / StateTonto Team🇨🇳APT / StateUNC3886🇨🇳APT / StateVOID MANTICORE🇮🇷APT / StateVolatile CedarAPT / StateVolt Typhoon🇨🇳APT / StateWinter Vivern🇷🇺APT / StateWizard Spider🇷🇺
Oracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x through 5.7.15; MariaDB before 5.5.51, 10.0.x before 10.0.27, and 10.1.x before 10.1.17; and Percona Server before 5.5.51-38.1, 5.6.x before 5.6.32-78.0, and 5.7.x before 5.7.14-7 allow local users to create arbitrary configurations and bypass certain protection mechanisms by setting general_log_file to a my.cnf configuration. NOTE: this can be leveraged to execute arbitrary code with root privileges by setting malloc_lib. NOTE: the affected MySQL version information is from Oracle's October 2016 CPU. Oracle has not commented on third-party claims that the issue was silently patched in MySQL 5.5.52, 5.6.33, and 5.7.15.
Affected products
n/a · n/apublic PoCs found — 11
exploitdbwww.exploit-db.com/exploits/40360unverifiedgithubgithub.com/MAYASEVEN/CVE-2016-6662★ 29githubgithub.com/Ashrafdev/MySQL-Remote-Root-Code-Execution★ 9githubgithub.com/boompig/cve-2016-6662★ 1githubgithub.com/meersjo/ansible-mysql-cve-2016-6662★ 1githubgithub.com/KosukeShimofuji/CVE-2016-6662★ 0githubgithub.com/konstantin-kelemen/mysqld_safe-CVE-2016-6662-patch★ 0vulncheckvulncheck.com/xdb/77badbece00eunverifiedvulncheckvulncheck.com/xdb/39e334b00224unverifiedvulncheckvulncheck.com/xdb/60add9bf4d4eunverifiedcve_referencewww.exploit-db.com/exploits/40360/unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://legalhackers.com/advisories/MySQL-Exploit-Remote-Root-Code-Execution-Privesc-CVE-2016-6662.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2058.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2059.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2060.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2061.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2062.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2077.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2130.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2131.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2595.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2749.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2927.html