Vulnerability record · CVE-2015-5287 · published 7 December 2015
CVE-2015-5287: ABRT abrt-hook-ccpp symlink privilege escalation
Redhat · Automatic Bug Reporting Tool
The abrt-hook-ccpp helper in Red Hat's Automatic Bug Reporting Tool (ABRT) before 2.7.1 follows symlinks on files with predictable names, letting a local user with certain permissions write to attacker-chosen paths. Because the helper runs with elevated privileges, this link-following flaw becomes a local privilege escalation.
Description
The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local users with certain permissions to gain privileges via a symlink attack on a file with a predictable name, as demonstrated by /var/tmp/abrt/abrt-hax-coredump or /var/spool/abrt/abrt-hax-coredump.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityLocal privilege escalation to full host compromise with public exploit code and CISA KEV listing, though it requires an existing local account.
What it is
The abrt-hook-ccpp helper in Red Hat's Automatic Bug Reporting Tool (ABRT) before 2.7.1 follows symlinks on files with predictable names, letting a local user with certain permissions write to attacker-chosen paths. Because the helper runs with elevated privileges, this link-following flaw becomes a local privilege escalation.
Impact
An attacker gains elevated privileges on the host, with high impact to confidentiality, integrity and availability per the CVSS vector. This is a full local root-level compromise of the affected system.
Attack surface
Reached locally: the vector is AV:L/PR:L/UI:N, so the attacker needs a local account with low privileges and no user interaction. No network or remote vector is described.
Exploitation
CISA added it to KEV with a due date of 2026-09-09, and multiple references are tagged Exploit, so public exploit code exists. EPSS is 0.04962 (91.7th percentile), indicating elevated but not top-tier predicted activity.
What to do
- Patch ABRT to 2.7.1 or later, or apply the vendor errata RHSA-2015-2505 for Red Hat Enterprise Linux.
- If patching is not immediately possible, restrict or disable the ABRT coredump hook and limit local shell access to trusted users.
- Harden the predictable paths named in the advisory (/var/tmp/abrt and /var/spool/abrt) so unprivileged users cannot create or replace entries there.
- Track the CISA KEV due date of 2026-09-09 and confirm remediation across all affected Red Hat and Oracle Linux assets.
Detection
- Monitor for symlinks or unexpected files created in /var/tmp/abrt and /var/spool/abrt, especially names resembling abrt-hax-coredump.
- Alert on abrt-hook-ccpp or sosreport processes writing outside expected coredump paths or spawning shells.
- Audit local account activity preceding privilege changes, correlating coredump events with new root sessions.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2015-5287 to the Known Exploited Vulnerabilities catalog on 26 August 2026 as "Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability". Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Federal deadline 9 September 2026.
Affected products
7 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2015-5287 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2015-5287), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.