
Privilege escaltion exploit script for Boardlight machine on HackTheBox. I had access as the Larissa user and ran this script from the /tmp directory; script has been adjusted accordingly.
This repository contains an exploit for CVE-2022-37706, a local privilege escalation vulnerability in Enlightenment v0.25.3 and earlier. The vulnerability exists due to improper handling of pathnames starting with the /dev/.. substring in the enlightenment_sys binary, which is SUID-root by default. By exploiting this behavior, attackers can execute arbitrary commands as root, resulting in full system control.
enlightenment_sys (setuid-root)<0.25.3).Clone or copy the exploit to the target system. Run from /tmp if using on the Boardlight HTB machine.
Save the exploit script as exploit.sh and make it executable:
chmod +x exploit.sh
Execute the script:
./exploit.sh
If successful, a root shell (#) will be opened.
Example Output
CVE-2022-37706 Exploit Initiated
[*] Using known path to vulnerable binary
[+] Vulnerable SUID binary found at: /usr/lib/x86_64-linux-gnu/enlightenment/utils/enlightenment_sys
[*] Preparing exploit directories and files
[+] Exploit script created. Attempting to escalate privileges
[+] Welcome to the rabbit hole :)
root@target:~#