CVE-2017-6554
CVE-2017-6554
pmmasterd in Quest Privilege Manager before 6.0.0.061, when configured as a policy server, allows remote attackers to write to arbitrary files and consequently execute arbitrary code with root privileges via an ACT_NEWFILESENT action.
Affected products
n/a · n/apublic PoCs found — 3
cve_referencepacketstormsecurity.com/files/142095/Quest-Privilege-Manager-6.0.0-Arbitrary-File-Write.htmlunverifiedcve_referencewww.exploit-db.com/exploits/41861/unverifiedexploitdbwww.exploit-db.com/exploits/41861unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
http://packetstormsecurity.com/files/142095/Quest-Privilege-Manager-6.0.0-Arbitrary-File-Write.htmlhttps://0xdeadface.wordpress.com/2017/04/07/multiple-vulnerabilities-in-quest-privilege-manager-6-0-0-xx-cve-2017-6553-cve-2017-6554/https://support.oneidentity.com/privilege-manager-for-unix/kb/SOL133824https://www.exploit-db.com/exploits/41861/http://www.securityfocus.com/bid/97686