Local Privilege Escalation Vulnerability in Lastore-Daemon from Deepin Technology
CVE-2016-15045
Key Information:
- Status
- Vendor
- CVE Published:
- 23 July 2025
Badges
What is CVE-2016-15045?
A local privilege escalation vulnerability exists in lastore-daemon, the package manager daemon for Deepin Linux, allowing any user in the sudo group to execute the InstallPackage method without needing password authentication. This flaw occurs in versions 0.9.53-1 and 0.9.66-1, where the default D-Bus configuration can be exploited by an attacker with shell access. They can craft a malicious .deb package containing a harmful post-install script and use dbus-send to install it, leading to arbitrary code execution with root privileges.
Affected Version(s)
Deepin Linux 0.9.53-1 (Deepin 15.5)
Deepin Linux 0.9.66-1 (Deepin 15.7)
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved