CVE-2015-3643 EXPLOIT
7.8
HIGH · CVSS 3.0 · EPSS 1.5% (pctl 74)
Patch early
A public exploit exists.
Description
usb-creator before 0.2.38.3ubuntu0.1 on Ubuntu 12.04 LTS, before 0.2.56.3ubuntu0.1 on Ubuntu 14.04 LTS, before 0.2.62ubuntu0.3 on Ubuntu 14.10, and before 0.2.67ubuntu0.1 on Ubuntu 15.04 allows local users to gain privileges by leveraging a missing call check_polkit for the KVMTest method.
Scoring
| CVSS | 7.8 (HIGH, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 1.53% — more likely to be exploited than 74% of all CVEs |
| Weakness | CWE-264 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2017-09-28 |
| Last modified | 2026-06-17 |
Affected (2)
| Vendor | Product |
|---|---|
| canonical | ubuntu linux |
| usb-creator project | usb-creator |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | usb-creator 0.2.x (Ubuntu 12.04/14.04/14.10) - Local Privilege Escalation | 2015-04-23 |
References
- http://www.openwall.com/lists/oss-security/2015/04/22/12
- http://www.openwall.com/lists/oss-security/2015/05/04/3
- http://www.securityfocus.com/bid/74304
- https://bazaar.launchpad.net/~usb-creator-hackers/usb-creator/trunk/revision/470
- https://usn.ubuntu.com/usn/usn-2576-1/
- https://usn.ubuntu.com/usn/usn-2576-2/
- https://www.exploit-db.com/exploits/36820/
- http://www.openwall.com/lists/oss-security/2015/04/22/12
- http://www.openwall.com/lists/oss-security/2015/05/04/3
- http://www.securityfocus.com/bid/74304
- https://bazaar.launchpad.net/~usb-creator-hackers/usb-creator/trunk/revision/470
- https://usn.ubuntu.com/usn/usn-2576-1/
- https://usn.ubuntu.com/usn/usn-2576-2/
- https://www.exploit-db.com/exploits/36820/
→ the Explorer · watch your stack · NVD