CVE-2015-5287

Red Hat Automatic Bug Reporting Tool: Privilege Escalation

As of , CVE-2015-5287 in Red Hat Automatic Bug Reporting Tool is on CISA's list of exploited vulnerabilities: CISA listed it on . Our patch-first group: Patch this week.

Exploited
Yes: CISA listed it on 26 August 2026
US federal deadline
9 September 202614 days after CISA listed it. US federal civilian agencies must fix it by then.
Used in ransomware campaigns
Not known to CISA
EPSS score
0.05Higher than 91% of the CVEs EPSS scores. EPSS estimates the chance of exploitation activity in the next 30 days.
Public exploit
1 Metasploit module and 3 Exploit-DB entries (3 verified)
Fix
Vendor advice: github.comLinks below, from CISA's entry.

What CISA says to do

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

CISA's required action

What the flaw is

Red Hat Automatic Bug Reporting Tool (ABRT) contains a privilege escalation vulnerability that could allow local users with certain permissions to gain privileges via a symlink attack on a file with a predictable name. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.

CISA's description

The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local users with certain permissions to gain privileges via a symlink attack on a file with a predictable name, as demonstrated by /var/tmp/abrt/abrt-hax-coredump or /var/spool/abrt/abrt-hax-coredump.

The CVE record's description, from redhat

CVE published
7 December 2015
Assigned by
redhat
CVSS
7.8 High (CVSS 3.1, from CISA-ADP)
CWE-59
Improper Link Resolution Before File Access ('Link Following')
CISA SSVC, exploitation
active
CISA SSVC, automatable
no
CISA SSVC, technical impact
total

Timeline

  1. Exploit-DB published an exploit (EDB-ID 38832).
  2. Exploit-DB published an exploit (EDB-ID 38835).
  3. The CVE record was published.
  4. Exploit-DB published an exploit (EDB-ID 47421).
  5. CISA added it to its list of exploited vulnerabilities.
  6. The US federal deadline to fix it.

Public exploits

Facts from Metasploit's module list and Exploit-DB's index; we never copy exploit code.

Read further