
An exploit for a 0-day vulnerability is already being sold on relevant forums.
On June 21, information appeared on one of the forums about the sale of an exploit for a zero-day vulnerability in the Linux GRUB bootloader, which allows local privilege escalation (LPE).
According to Dark Web Intelligence, the attacker claims to have found a vulnerability in GRUB that allows bypassing authentication mechanisms to gain root access to the system.
According to a post by a member of a dark forum under the nickname 'Cas', the vulnerability affects GRUB—a critical component of most Linux systems that manages the boot process—allowing attackers to install hidden and persistent malware, which can be quite challenging to detect and remove. The exploit is being sold for $90,000.
It is worth noting that GRUB has been targeted in the past. In 2015, a vulnerability known as CVE-2015-8370 was discovered, allowing authentication to be bypassed by pressing the backspace key 28 times during the username input stage in GRUB. This vulnerability affected GRUB versions from 1.98 to 2.02 and was widely exploited until a patch was released. In 2020, another vulnerability—CVE-2020-10713, also known as BootHole—was identified, enabling malware to be installed during the boot process.
Major Linux distributions such as Debian, RedHat, and Ubuntu quickly released advisories and patches for previous GRUB vulnerabilities, and are likely to do the same this time. However, the issue is compounded by the fact that the vulnerability has been discovered by attackers rather than ethical hackers. This means that its detection and remediation by security researchers may take significantly longer.
Source: linux.org.ru
