
self cleaning CVE-2025-27591 Poc that grants a root reverse shell instead of modifying passwd files
below versions < v0.9.0 are vulnerable to a local privilege escalation vulnerability duo to the fact that the program creates a world-writable log file, an a world writable log file instead, the attacker can replace the log file with a symblink to any system-critical file and be able to edit it in order to login as root
the following vulnerablity targets /etc/ld.so.preload to pop a reverse shell as root, cleaning all indicators of compromise before doing so
the vulnerability is only exploitable on systems that ship with installation packages that don't create the log file directory, or create it with a specific permissions, and/or rely on the program to create the log directory instead, such systems include : ubuntu, arch linux, gentoo ..
change the IP and port on the exploit code and compile it on your machine
$ bash compile.sh
then copy it the shared library and the exploit script to the same folder on the remote machine and run it
$ bash exploit.sh