Zero-day vulnerability in cPanel

Format string vulnerability
CVE-2017-5613

The exploit code was disclosed by the Shadow Brokers leak dubbed ElegantEagle, exploiting vulnerability in cgiemail.

Known malware:

ElegantEagle exploit

Vulnerability details

Advisory: SB2017011801 - Multiple vulnerabilities in cPanel

Vulnerable component: cPanel

CVE-ID: CVE-2017-5613

CVSSv3 score: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:H/RL:O/RC:C

CWE-ID: CWE-134 - Use of Externally-Controlled Format String

Description:

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a format string error within cgiemail and cgiecho binaries when processing template files. A remote authenticated attacker can create a specially crafted file, containing form string specifiers and execute arbitrary code on the target system.

Successful exploitation may allow an attacker to compromise vulnerable system.

Note: this vulnerability has been exploited in the wild and was disclosed by the Shadow Brokers leak. The exploit is known as ElegantEagle.