CVE-2024-36587 is a local privilege escalation vulnerability affecting DNSCrypt-proxy versions 2.0.0alpha9 through 2.1.5. The issue is caused by insecure file permissions that allow a non-privileged local attacker to overwrite the dnscrypt-proxy binary. If the binary is owned by root and subsequently executed in a privileged context, the attacker can replace it with a malicious payload and obtain root-level execution.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository provides a proof-of-concept (PoC) exploit for CVE-2024-36587, a local privilege escalation vulnerability in dnscrypt-proxy (versions v2.0.0-alpha9 to v2.1.5). The exploit leverages a binary planting technique: when the dnscrypt-proxy service is installed, it may trust and execute binaries from the current directory, allowing an attacker to insert a malicious binary (in this case, a script named 'id'). The repository includes a Dockerfile that sets up a vulnerable environment, clones the vulnerable version of dnscrypt-proxy, and plants a malicious 'id' script that, when executed, writes a marker file to '/tmp/poc_was_here'. The docker-compose.yaml file is used to build and run the container with the necessary privileges. The README.md provides detailed instructions and context, including references to the official CVE and the upstream repository. The main exploit capability is local privilege escalation via binary planting, and the PoC demonstrates successful exploitation by creating a file as proof of code execution with elevated privileges.
2 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.