Remote Command Execution Vulnerability in ISC DHCP Client
CVE-2011-0997
Currently unrated
Key Information:
Badges
๐พ Exploit Exists๐ก Public PoC๐ฃ EPSS 73%
What is CVE-2011-0997?
The ISC DHCP Client, specifically versions ranging from 3.0.x to 4.2.x before 4.2.1-P1, contains a vulnerability that permits remote attackers to execute arbitrary commands. This can be achieved through the insertion of shell metacharacters within a hostname supplied in a DHCP message to dhclient. By exploiting this flaw, an attacker can manipulate the system to execute unintended commands, potentially leading to unauthorized access or control over the affected system.
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.