← Vulnerability feed

Vulnerability record · CVE-2015-5287 · published 7 December 2015

CVE-2015-5287: ABRT abrt-hook-ccpp symlink privilege escalation

Redhat · Automatic Bug Reporting Tool

The abrt-hook-ccpp helper in Red Hat's Automatic Bug Reporting Tool (ABRT) before 2.7.1 follows symlinks on files with predictable names, letting a local user with certain permissions write to attacker-chosen paths. Because the helper runs with elevated privileges, this link-following flaw becomes a local privilege escalation.

7.8 CVSS 3.1 High CISA KEV since 26 Aug 2026 EPSS 5.0% · top 8.1% CWE-59 · Link following
7.8CVSS 3.1 base score, v2 6.9
5.0%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
7Affected product versions listed by NVD
18References, 4 tagged exploit
27 Aug 2026Last modified by NVD

Description

The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local users with certain permissions to gain privileges via a symlink attack on a file with a predictable name, as demonstrated by /var/tmp/abrt/abrt-hax-coredump or /var/spool/abrt/abrt-hax-coredump.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityLocal privilege escalation to full host compromise with public exploit code and CISA KEV listing, though it requires an existing local account.

What it is

The abrt-hook-ccpp helper in Red Hat's Automatic Bug Reporting Tool (ABRT) before 2.7.1 follows symlinks on files with predictable names, letting a local user with certain permissions write to attacker-chosen paths. Because the helper runs with elevated privileges, this link-following flaw becomes a local privilege escalation.

Impact

An attacker gains elevated privileges on the host, with high impact to confidentiality, integrity and availability per the CVSS vector. This is a full local root-level compromise of the affected system.

Attack surface

Reached locally: the vector is AV:L/PR:L/UI:N, so the attacker needs a local account with low privileges and no user interaction. No network or remote vector is described.

Exploitation

CISA added it to KEV with a due date of 2026-09-09, and multiple references are tagged Exploit, so public exploit code exists. EPSS is 0.04962 (91.7th percentile), indicating elevated but not top-tier predicted activity.

What to do

  • Patch ABRT to 2.7.1 or later, or apply the vendor errata RHSA-2015-2505 for Red Hat Enterprise Linux.
  • If patching is not immediately possible, restrict or disable the ABRT coredump hook and limit local shell access to trusted users.
  • Harden the predictable paths named in the advisory (/var/tmp/abrt and /var/spool/abrt) so unprivileged users cannot create or replace entries there.
  • Track the CISA KEV due date of 2026-09-09 and confirm remediation across all affected Red Hat and Oracle Linux assets.

Detection

  • Monitor for symlinks or unexpected files created in /var/tmp/abrt and /var/spool/abrt, especially names resembling abrt-hax-coredump.
  • Alert on abrt-hook-ccpp or sosreport processes writing outside expected coredump paths or spawning shells.
  • Audit local account activity preceding privilege changes, correlating coredump events with new root sessions.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2015-5287 to the Known Exploited Vulnerabilities catalog on 26 August 2026 as "Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability". Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Federal deadline 9 September 2026.

Affected products

7 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://packetstormsecurity.com/files/154592/ABRT-sosreport-Privilege-Escalation.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2015-2505.html Vendor Advisory
http://www.openwall.com/lists/oss-security/2015/12/01/1 Exploit
http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html Third Party Advisory
http://www.securityfocus.com/bid/78137 Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=1266837 Exploit
https://github.com/abrt/abrt/commit/3c1b60cfa62d39e5fff5a53a5bc53dae189e740e Patch
https://www.exploit-db.com/exploits/38832/ Mailing ListThird Party Advisory
http://packetstormsecurity.com/files/154592/ABRT-sosreport-Privilege-Escalation.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2015-2505.html Vendor Advisory
http://www.openwall.com/lists/oss-security/2015/12/01/1 Exploit
http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html Third Party Advisory
http://www.securityfocus.com/bid/78137 Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=1266837 Exploit
https://github.com/abrt/abrt/commit/3c1b60cfa62d39e5fff5a53a5bc53dae189e740e Patch
https://www.exploit-db.com/exploits/38832/ Mailing ListThird Party Advisory
https://blog.talosintelligence.com/uat-10147-chinese-speaking-adversary-integrates-agentic-ai-into-post-compromise-opera Third Party Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2015-5287 Third Party AdvisoryUS Government Resource

Track CVE-2015-5287 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-5544OpenSLP heap out-of-bounds write in VMware ESXi and Horizon DaaSOpenSLP as shipped in VMware ESXi and Horizon DaaS contains a heap overwrite (out-of-bounds write) flaw. VMware rates it Critical with a maximum CVSS…KEVEPSS 97%analysed9.8CVE-2019-11043PHP-FPM buffer overflow enables remote code executionPHP-FPM in certain configurations writes past allocated buffers into FCGI protocol data space, an out-of-bounds write (CWE-787, CWE-120). It affects …KEVEPSS 100%analysed9.8CVE-2018-14667RichFaces Framework EL injection enables unauthenticated remote code executionRichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language injection through the UserResource resource. A remote, unauthenticated att…KEVEPSS 74%analysed9.8CVE-2016-4171Adobe Flash Player unspecified remote code execution flawCVE-2016-4171 is an unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier that allows remote attackers to execute arbitrary code thr…KEVEPSS 20%analysed9.8CVE-2016-4117Adobe Flash Player unspecified vectors allow arbitrary code executionAdobe Flash Player 21.0.0.226 and earlier contains a critical flaw that lets remote attackers execute arbitrary code through unspecified vectors. Ado…KEVEPSS 94%analysed9.8CVE-2016-3427Oracle Java SE JMX Improper Access Control VulnerabilityCVE-2016-3427 is an unspecified vulnerability in Oracle Java SE 6u113, 7u99, 8u77, Java SE Embedded 8u77, and JRockit R28.3.9, reached through vector…KEVEPSS 92%analysed9.8CVE-2015-2590Oracle Java SE Libraries flaw allows remote code executionCVE-2015-2590 is an unspecified vulnerability in the Libraries component of Oracle Java SE 6u95, 7u80, 8u45 and Java SE Embedded 7u75, 8u33. The reco…KEVEPSS 25%analysed9.8CVE-2015-5123Adobe Flash Player ActionScript 3 BitmapData use-after-freeAdobe Flash Player contains a use-after-free in the ActionScript 3 BitmapData class, triggered by crafted Flash content that overrides a valueOf func…KEVEPSS 19%analysed

Source: NIST National Vulnerability Database (record CVE-2015-5287), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.