Proof of concept exploit was really simple, and if anybody is interested, I created one yesterday - https://github.com/arthepsy/CVE-2021-4034. But I guess, today the Internet will flow with PoCs and they won’t be hard to find.
Nice. Yours looks broadly similar to the one that was making the rounds yesterday afternoon. They weren’t hard to find yesterday. I suspect they’ll be weaponized today :-)
It’s already been refined to this which is still super noisy but doesn’t need a compiler on the target system. I suspect that one is good enough to make a metasploit module.
Proof of concept exploit was really simple, and if anybody is interested, I created one yesterday - https://github.com/arthepsy/CVE-2021-4034. But I guess, today the Internet will flow with PoCs and they won’t be hard to find.
Nice. Yours looks broadly similar to the one that was making the rounds yesterday afternoon. They weren’t hard to find yesterday. I suspect they’ll be weaponized today :-)
It’s already been refined to this which is still super noisy but doesn’t need a compiler on the target system. I suspect that one is good enough to make a metasploit module.