
a C exploit for CVE-2025-27591, which allow an attacker to escalate privilege to root.
Basically below tool allow for universal modification on its log file which lead to privilege escalation as root.
The log file created by below is world-writable, allowing any user to modify or replace it.
An attacker can exploit this by creating a symbolic link from the log file to /etc/passwd.
If the attacker can trigger an error in below that logs arbitrary input, and crafts that input in
the format of a valid /etc/passwd entry, they can inject a new root user into the system.
In order for the exploit to work the attacker should be able to execute the below command as it should be run
as root then the user must have sudo permission or a way to run it.
git clone https://github.com/Cythonic1/CVE-2025-27591
cd CVE-2025-27591
gcc -static -W -Wall main.c ./libcrypt.a -o exploit
./exploit <username> <password>