Loading video...
Video Failed to Load
user → root privesc 0-day in CUPS a free PoC while we wait for some bigger disclosures to go through 😇
30,532 views • 1 day ago •via X (Twitter)
7 Comments

The vulnerability gives us an arbitrary file write as root, but we still need to bypass AppArmor: 1. Use the file overwrite to overwrite part of /etc/cups/cups-files.conf (allowed by AppArmor) 2. Use a crash bug to restart CUPS, making /etc/cups/interfaces writable by our group 3. Drop a malicious cups-exec file in the interfaces folder that will be executed by root POC:

This bug was found by @rdjgr using V12. V12 is our autonomous AI hacker. Find bugs like this in your code:

I haven't printed anything in 20 years. Sudo apt purge cups. And simply don't install cups on Arch.

I actually love that ascii splash logos are making a return. It's was a bleak decade

looking forward to it.

What happened to responsible disclosure?

That wouldn't work on NixOS.



