Vulnerability in the NFS server of FreeBSD and OpenBSD leading to remote code execution

A critical vulnerability (CVE-2024-29937) has been identified in the NFS server implementation used in BSD systems, allowing for remote code execution with root privileges on the server. The issue affects all releases of OpenBSD and FreeBSD, up to OpenBSD 7.4 and FreeBSD 14.0-RELEASE. Detailed information about the vulnerability is not yet disclosed; it is only known that the issue is caused by a logical error unrelated to memory corruption. It is noted that this vulnerability can easily be exploited for attacks on systems using NFS, and according to a video demonstration, it allows for full access to the root file system. server Exploitation requires permissions to mount NFS shares. A report on the nature of the vulnerability will be presented on April 18 at the T2'24 conference.

Play video


Source: opennet.ru
Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster