Enlightenment versions before 0.25.4 contain a pathname-handling vulnerability in the setuid-root enlightenment_sys component. A system library function mishandles pathnames beginning with a /dev/.. substring, enabling a local user to obtain elevated privileges.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
5 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
Repository is a minimal local privilege-escalation exploit for CVE-2022-37706 affecting Enlightenment on Linux, specifically the setuid-root enlightenment_sys component before version 0.25.4. It contains two files: a README describing the vulnerability and impact, and a single Bash exploit script, root.sh, which is the operational entry point. The exploit script first searches the filesystem for a setuid enlightenment_sys binary using find. If found, it prepares temporary directories under /tmp and creates an executable helper file /tmp/exploit containing /bin/sh. It then invokes the vulnerable binary with /bin/mount and a crafted source path /dev/../tmp/;/tmp/exploit designed to abuse unsafe pathname validation involving the /dev/.. prefix. Successful exploitation results in execution of a root shell. This is a real exploit rather than a detector: it performs exploitation steps and includes a hardcoded payload. There are no network capabilities, C2 endpoints, or remote targets; the attack vector is strictly local. The code is simple and operational, but not highly modular or framework-based.
This repository contains a single Metasploit module (Ruby file) that exploits a local privilege escalation vulnerability (CVE-2022-37706) in the Enlightenment window manager on Ubuntu Linux. The exploit targets the 'enlightenment_sys' binary, which must be SUID and present on the system. The module works by uploading a payload (default: Meterpreter reverse shell) to a writable directory (default: /tmp), then exploiting a command injection vulnerability in the way 'enlightenment_sys' handles mount commands. The exploit is operational and provides root access if successful. The code is structured as a standard Metasploit local exploit module, with functions for checking the target, uploading the payload, and executing the exploit. The only endpoints referenced are local file paths relevant to the exploitation process.
This repository provides a local privilege escalation exploit for CVE-2022-37706, targeting Enlightenment v0.25.3 and earlier on Linux systems. The exploit abuses improper pathname handling in the SUID-root 'enlightenment_sys' binary. The repository contains two files: a detailed README.md explaining the vulnerability, exploitation steps, and usage instructions, and a Bash script (exploit.sh) that automates the attack. The script checks for the presence and executability of the vulnerable binary, sets up malicious directories and a payload script, and then invokes the vulnerable binary with a specially crafted path to escalate privileges. If successful, it spawns a root shell. The script also includes cleanup routines to remove evidence after exploitation. The exploit requires local access to a vulnerable system and does not involve any network communication. All endpoints are local file paths relevant to the exploitation process.
This repository provides a local privilege escalation exploit for CVE-2022-37706, targeting the Enlightenment window manager's SUID binary 'enlightenment_sys' (version 0.25.3-1) on Linux systems. The exploit leverages a command injection vulnerability in the way the binary handles mount arguments, allowing an attacker to execute arbitrary commands as root. The repository contains three files: a detailed README.md explaining the vulnerability and exploitation process, a PublicReferenceURL.txt with a technical summary and PoC, and the main exploit script (exploit.sh). The exploit script locates the vulnerable SUID binary, prepares the necessary directories and payload, writes a shell script to /tmp/exploit, and then invokes enlightenment_sys with crafted arguments to trigger the vulnerability and spawn a root shell. The attack is local and requires the attacker to have access to a system with the vulnerable Enlightenment version installed. The exploit is operational, providing a working root shell if successful, and is not part of any exploit framework.
This repository contains a proof-of-concept (PoC) local privilege escalation exploit for CVE-2022-37706, targeting the Enlightenment window manager's 'enlightenment_sys' SUID binary on Linux systems. The exploit is implemented as a Bash script ('exploit.sh') that searches for the vulnerable binary, prepares a shell payload at '/tmp/exploit', and manipulates mount parameters and file paths to trigger the vulnerability. If successful, the script spawns a root shell, granting the attacker full system control. The repository also includes a README.md that explains the vulnerability, its impact, and mitigation steps. The exploit requires local access to a system with the vulnerable Enlightenment installation and does not target remote systems or network services.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.