Description
The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local users with certain permissions to gain privileges via a symlink attack on a file with a predictable name, as demonstrated by /var/tmp/abrt/abrt-hax-coredump or /var/spool/abrt/abrt-hax-coredump.
In plain language
AI Act nowCVE-2015-5287 is a local privilege-escalation bug in ABRT (before 2.7.1) where a user can trick a helper program into following a fake “shortcut” (symlink) and overwrite system files—your small business should patch if you have ABRT installed and local users with the required permissions.
In ABRT before 2.7.1, abrt-hook-ccpp can be abused via a symlink attack on predictable temporary paths (e.g., /var/tmp/abrt/abrt-hax-coredump or /var/spool/abrt/abrt-hax-coredump) by a local user with certain permissions, enabling privilege escalation by overwriting/modifying files as a more-privileged process.
What to do now
- Check whether you run “automatic bug reporting tool” (ABRT) and identify installed versions prior to 2.7.1.
- If your ABRT version is before 2.7.1, upgrade ABRT to 2.7.1 or newer using your vendor’s package update path.
- If you cannot patch immediately, restrict local access so only trusted administrators can create/modify files in ABRT’s temporary/spool directories used by the predictable paths.
- Verify after updating that ABRT is no longer using the vulnerable code path (confirm ABRT version is 2.7.1+).
CVSS Vector Breakdown
AV:LAttack VectorAC:LAttack ComplexityPR:LPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
- Previously patched Citrix NetScaler flaw exploited in the wild (CVE-2026-8452)en-us·Help Net Security· Exploited Citrix NetScaler ADC rce
- CISA Adds Six Exploited Flaws to KEV, Including NetScaler, Linux, and SQL Server Bugsen·The Hacker News· Exploited Citrix NetScaler ADC zero-day
- UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkiten·The Hacker News· Exploited UAT-10147 malware
- UAT-10147: Chinese-speaking adversary integrates agentic AI into post-compromise operationsen·Cisco Talos· Exploited Windows Server UAT-10147
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2015-5287 and every CVE in our database. Create a free account — no credit card required.
Create Free Account