Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2022-37706 — Privilege escaltion exploit script for Boardlight machine on HackTheBox. I had access as the Larissa user and ran this script from the /tmp directory; script has been adjusted accordingly. | Kitploit
Tools/GitHubGitHub/d3ndr1t30x/cve-2022-37706
Privilege EscalationVulnerability AnalysisExploitationPost-ExploitationPenetration TestingRed Teaming
GitHubd3ndr1t30x/cve-2022-37706

CVE-2022-37706

Privilege escaltion exploit script for Boardlight machine on HackTheBox. I had access as the Larissa user and ran this script from the /tmp directory; script has been adjusted accordingly.

View Repository
1491 year agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2022-37706 Exploit: Enlightenment v0.25.3 Privilege Escalation

Description

This repository contains an exploit for CVE-2022-37706, a local privilege escalation vulnerability in Enlightenment v0.25.3 and earlier. The vulnerability exists due to improper handling of pathnames starting with the /dev/.. substring in the enlightenment_sys binary, which is SUID-root by default. By exploiting this behavior, attackers can execute arbitrary commands as root, resulting in full system control.

Exploit Details

  • Vulnerable Binary: enlightenment_sys (setuid-root)
  • CVE: CVE-2022-37706
  • Severity: Critical
  • Tested On: Ubuntu 22.10 (Kinetic Kudu)

Exploit Workflow

  1. The vulnerable binary is located, ensuring it is SUID and accessible.
  2. Malicious directories and payloads are created to abuse the binary's improper pathname handling.
  3. The exploit triggers the binary with crafted mount options, executing the payload as root.
  4. Cleanup routines are included to remove evidence after exploitation.

Usage

Prerequisites

  • Access to the vulnerable system as a low-privileged user.
  • Vulnerable version of Enlightenment installed (<0.25.3).

Exploit Execution

  1. Clone or copy the exploit to the target system. Run from /tmp if using on the Boardlight HTB machine.

  2. Save the exploit script as exploit.sh and make it executable: chmod +x exploit.sh

  3. Execute the script: ./exploit.sh

  4. If successful, a root shell (#) will be opened.

Example Output CVE-2022-37706 Exploit Initiated [*] Using known path to vulnerable binary [+] Vulnerable SUID binary found at: /usr/lib/x86_64-linux-gnu/enlightenment/utils/enlightenment_sys [*] Preparing exploit directories and files [+] Exploit script created. Attempting to escalate privileges [+] Welcome to the rabbit hole :) root@target:~#

Download Tool