CVE-2024-27766 describes a disputed issue in MariaDB 11.1 involving the User Defined Function library lib_mysqludf_sys.so. The reported behavior is that a remote attacker can execute arbitrary code through this UDF functionality. The issue is disputed by the MariaDB Foundation on the grounds that exploitation does not cross a privilege boundary, indicating the behavior may be inherent to the capabilities already available to a sufficiently privileged database user rather than a defect enabling unauthorized privilege gain. Based on the available information, the reported weakness is best characterized as exposure of dangerous functionality to a highly privileged context rather than a clearly established memory-safety or input-validation flaw.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small exploit PoC for CVE-2024-27766 targeting MariaDB 11.1 on Windows. It contains two files: a README describing the vulnerability, prerequisites, and SQL registration syntax, and a single C source file implementing the malicious UDF. The exploit is not a standalone remote exploit script; instead, it is a malicious MariaDB UDF payload intended to be compiled as a DLL and loaded by a privileged database user. The core capability is arbitrary OS command execution via the exported UDF function do_system. Unlike the original referenced PoC, this modified version uses _popen() instead of system(), reads stdout with fgets(), concatenates the output into a heap-allocated buffer, and returns that buffer as a char* result to MariaDB. This means SQL queries can directly retrieve command output inline, rather than only receiving an exit code. The code also includes init and deinit handlers for MariaDB UDF lifecycle management, with deinit freeing the allocated output buffer. There are no hardcoded network callbacks, C2 endpoints, or external URLs in the exploit code itself. The main fingerprintable artifacts are the UDF name do_system, the DLL name do_system.dll, and the requirement to place the DLL in MariaDB's plugin directory before issuing a CREATE FUNCTION ... SONAME statement. Operationally, exploitation requires pre-existing high database privileges, so this is best characterized as an operational post-auth RCE/enabler rather than an unauthenticated remote exploit.
This repository contains a proof-of-concept exploit for MariaDB 11.1 on Windows, demonstrating how to achieve remote code execution via a malicious User-Defined Function (UDF). The exploit consists of a C source file (`poc.c`) that implements a UDF named `do_system`, which executes arbitrary system commands provided as arguments. The README.md provides detailed, step-by-step instructions for compiling the UDF, converting it to a shared object, and deploying it to the MariaDB plugin directory using SQL commands. The attacker must have sufficient privileges to write to the plugin directory and create new functions in the database. Once deployed, the attacker can execute arbitrary commands on the server by invoking the UDF from SQL. The exploit targets MariaDB 11.1 on Windows, specifically referencing the default plugin directory path. No CVE is referenced, but the technique is a classic UDF-based privilege escalation and code execution attack.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.