CVE-2018-1165
published 2018-02-21CVE-2018-1165: This vulnerability allows local attackers to escalate privileges on vulnerable installations of Joyent SmartOS release-20170803-20170803T064301Z. An attacker…
PriorityP433high7CVSS 3.1
AVLACHPRLUINSUCHIHAH
EPSS
0.50%
39.5th percentile
This vulnerability allows local attackers to escalate privileges on vulnerable installations of Joyent SmartOS release-20170803-20170803T064301Z. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the SMB_IOC_SVCENUM IOCTL. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length, heap-based buffer. An attacker can leverage this vulnerability to execute code under the context of the host OS. Was ZDI-CAN-4983.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| joyent | joyent_smartos | — | — |
| joyent | smartos | — | — |
| oracle | solaris | — | — |
| oracle | zfs_storage_appliance | — | — |
CVSS provenance
nvdv3.17.0HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
vendor_oracle7.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Systems Risk Matrix: SMB Server Kernel Module — CVE-2018-1165
vendor_oracle·2020-04-15·CVSS 7.0
CVE-2018-1165 [HIGH] Oracle Oracle Systems Risk Matrix: SMB Server Kernel Module — CVE-2018-1165
Oracle Oracle Systems Risk Matrix: SMB Server Kernel Module vulnerability
CVE: CVE-2018-1165
CVSS: 7.0
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpuapr2020 (APR 2020)
GHSA
GHSA-26qq-h2w9-r3wv: This vulnerability allows local attackers to escalate privileges on vulnerable installations of Joyent SmartOS release-20170803-20170803T064301Z
ghsa_unreviewed·2022-05-13
CVE-2018-1165 [HIGH] CWE-787 GHSA-26qq-h2w9-r3wv: This vulnerability allows local attackers to escalate privileges on vulnerable installations of Joyent SmartOS release-20170803-20170803T064301Z
This vulnerability allows local attackers to escalate privileges on vulnerable installations of Joyent SmartOS release-20170803-20170803T064301Z. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the SMB_IOC_SVCENUM IOCTL. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length, heap-based buffer. An attacker can leverage this vulnerability to execute code under the context of the host OS. Was ZDI-CAN-4983.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://help.joyent.com/hc/en-us/articles/360000124928https://www.oracle.com/security-alerts/cpuapr2020.htmlhttps://zerodayinitiative.com/advisories/ZDI-18-158https://help.joyent.com/hc/en-us/articles/360000124928https://www.oracle.com/security-alerts/cpuapr2020.htmlhttps://zerodayinitiative.com/advisories/ZDI-18-158
2018-02-21
Published