Canonical snapd before version 2.37.1 incorrectly performed socket owner validation, allowing an attacker to run arbitrary commands as root. This issue affects: Canonical snapd versions prior to 2.37.1.
PoC: dirty_sock
Linux privilege escalation exploit via snapd (CVE-2019-7304)
PoC: CVE-2019-7304_DirtySock
Payload Generator
PoC: dirty_sock
Local Privilege Escalation via snapd (CVE-2019-7304) Remastered PoC exploit
PoC: Document-Linux-Privilege-Escalation
Exploiting the vulnerability called "Dirty_Sock" (CVE-2019-7304) in the REST API for Canonical's snapd daemon.
PoC: snap_priv_esc
Another implementation for linux privilege escalation exploit via snap(d) (CVE-2019-7304)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Get alerted for CVEs like this
Register your stack and get notified within minutes when a matching CVE drops.
Start monitoring free