elttam disclosed an attacker-controlled format-string vulnerability in the tac_plus TACACS+ daemon, affecting the Facebook fork F4.0.4.28-7fb and the Shrubbery code tree. A crafted AUTHEN/START request can inject data into session.port; a malformed continuation can then cause send_authen_error() to pass the attacker-influenced buffer directly to report() as a format string. The researchers demonstrated code execution on an unhardened 32-bit build by overwriting the Global Offset Table entry for free(), while warning that modern exploit mitigations raise the bar but do not eliminate the underlying vulnerability.
The attack can be conducted before authentication and is strengthened by a TCP/49 shared-secret oracle: predictable error responses allow offline guessing of weak TACACS+ pre-shared secrets without intercepted traffic or valid credentials. After recovering the secret, an attacker can generate an obfuscated exploit packet; a trusted TACACS+ client that relays attacker-controlled values could also be abused. Organizations using affected tac_plus deployments should identify exposed TCP/49 services, apply vendor fixes or mitigations, restrict TACACS+ access to trusted management networks, and rotate weak shared secrets.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
The research disclosed that a truncated AUTHEN/START request causes a predictable, shared-secret-obfuscated error response, enabling reachable TCP/49 attackers to verify shared-secret guesses offline. It demonstrated recovery of the weak secret "supersecret" with a rockyou.txt-style wordlist, allowing construction of obfuscated exploit packets.
elttam published research describing an unauthenticated format-string vulnerability in tac_plus, principally affecting the Facebook F4.0.4.28-7fb fork and the Shrubbery tree. The research shows that a malicious TACACS+ AUTHEN/START port field and malformed continuation can trigger a pre-authentication memory-write primitive and demonstrates code execution in an unhardened 32-bit environment.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.