CORE IMPACT v10 - Exploits Update (Fri Mar 12 2010)
Sudoedit Privilege Escalation Exploit Update
Exploits/Local [Solaris]
Fri Mar 12 2010
This module exploits a missing verification of the path in the command "sudoedit", provided by the sudo package. This can be exploited to execute any command as root including a shell, allowing an unprivileged process to elevate its privileges to root. This update adds Solaris 10, AIX 5.3 and FreeBSD 7 as supported targets.
Exploits Vulnerabiltiy: CVE-2010-0426











