In OpenBSD 6.6, when S/Key or YubiKey authentication is enabled (a non-default configuration), local users who are members of the 'auth' group can escalate privileges to root. This is due to insufficient file ownership and permission checks, allowing members of the 'auth' group to write to root's authentication files in /etc/skey or /var/db/yubikey, even though these files do not need to be owned by root.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository provides a local privilege escalation exploit for OpenBSD systems, targeting CVE-2019-19520 and CVE-2019-19522. The exploit is structured in three files: a README.md with detailed background and exploitation steps, a C proof-of-concept (poc.c) that is compiled into a shared object to be loaded by the vulnerable xlock binary, and a shell script (x.sh) that automates the process of creating a malicious S/Key entry for the root user. The attack proceeds in two stages: first, the attacker uses the C payload to gain 'auth' group privileges via xlock; second, the attacker leverages these privileges to add authentication keys for root in S/Key or YubiKey, ultimately allowing root access. The exploit requires local access and specific OpenBSD configurations, and demonstrates a clear path from unprivileged user to root. The repository contains no detection scripts or fake code, and the exploit is operational, providing a working privilege escalation chain.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.