peter bassill · operator
$ cve CVE-2015-5287 JSON

CVE-2015-5287 KEV EXPLOIT

7.8
HIGH · CVSS 3.1 · EPSS 5% (pctl 92)

Patch first

On CISA KEV — known exploited in the wild, due 2026-09-09.

Description

The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local users with certain permissions to gain privileges via a symlink attack on a file with a predictable name, as demonstrated by /var/tmp/abrt/abrt-hax-coredump or /var/spool/abrt/abrt-hax-coredump.

Scoring

CVSS7.8 (HIGH, v3.1)
VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS4.96% — more likely to be exploited than 92% of all CVEs
WeaknessCWE-59
On CISA KEVyes — remediate by 2026-09-09
Public exploityes
Published2015-12-07
Last modified2026-08-27

CISA KEV

NameRed Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability
Added2026-08-26
Due2026-09-09
Vendor / productRed Hat / Automatic Bug Reporting Tool
Ransomware usenone reported

Affected (7)

VendorProduct
oraclelinux
redhatautomatic bug reporting tool
redhatenterprise linux
redhatenterprise linux desktop
redhatenterprise linux hpc node
redhatenterprise linux server
redhatenterprise linux workstation

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD