HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) before 4.0.24 uses weak permissions for the sudo helper scripts, allows local users to execute arbitrary code with root privileges by overwriting one of the scripts.
During installation, installed file permissions are set to allow anyone to modify those files.
Link | Tags |
---|---|
http://seclists.org/fulldisclosure/2017/Aug/0 | third party advisory mailing list |
https://www.exploit-db.com/exploits/43224/ | exploit |
https://m4.rkw.io/blog/cve201711741-local-root-privesc-in-hashicorp-vagrantvmwarefusion--4023.html | third party advisory exploit |