HP Performance Monitoring xglance Privilege Escalation
Posted by deepcore on May 5, 2020 – 7:33 pm
This Metasploit module is an exploit that takes advantage of xglance-bin, part of HP’s Glance (or Performance Monitoring) version 11 and subsequent, which was compiled with an insecure RPATH option. The RPATH includes a relative path to -L/lib64/ which can be controlled by a user. Creating libraries in this location will result in an escalation of privileges to root.
Post a reply
You must be logged in to post a comment.