Intel Data Center Manager 5.1 Local Privilege Escalation
Posted by deepcore on December 10, 2022 – 5:51 pm
The latest version (5.1) and all prior versions of Intel’s Data Center Manager are vulnerable to a local privileges escalation vulnerability using the application user “dcm” used to run the web application and the rest interface. An attacker who gained remote code execution using this dcm user (i.e., through Log4j) is then able to escalate their privileges to root by abusing a weak sudo configuration for the “dcm” user.
Post a reply
You must be logged in to post a comment.