Sudo Exiftool Privilege Escalation
Sudo exiftool command might be vulnerable to privilege escalation (PrivEsc).
Investigation
If we can execute "exiftool" command as root, we can gain access to privileges.
Arbitrary Code Execution (CVE-2021-22204) version 7.44+
Reference: https://vk9-sec.com/exiftool-12-23-arbitrary-code-execution-privilege-escalation-cve-2021-22204/
Check the exiftool version. If the exiftool version is later than 7.44, we can execute arbitrary code.
Exploitation
In local machine, create the payload in a file named “exploit”.
Next, compress the file.
Then create the DjVu file using the compressed file.
Now we have “exploit.djvu” file. Trasfer the file to the target machine and run exiftool as root given the DjVufile.
We should get a root shell.
Last updated