{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aredhatautomatic_bug_reporting_tool/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:redhat:automatic_bug_reporting_tool:*:*:*:*:*:*:*:*","cpe:2.3:o:oracle:linux:7:*:*:*:*:*:*:*","cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*","cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*","cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*","cpe:2.3:o:redhat:enterprise_linux_hpc_node:7.0:*:*:*:*:*:*:*","cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*","cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.8,"id":"CVE-2015-5287"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Automatic Bug Reporting Tool"],"_cs_severities":["medium"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Red Hat"],"content_html":"\u003cp\u003eCVE-2015-5287 is a privilege escalation vulnerability within the Red Hat Automatic Bug Reporting Tool (ABRT), an open-source utility designed to collect and report diagnostic data. An attacker with local access can exploit improper file handling during the reporting process, specifically through a symlink attack targeting files with predictable names. By redirecting file operations to sensitive system files, a malicious local user may gain escalated privileges on the host system. This vulnerability has been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. Given that ABRT is frequently installed on RHEL-based systems, security teams should assess current exposure, particularly on systems running older or end-of-life software versions, as indicated by CISA BOD 26-04.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows a local user to escalate privileges beyond their current authorization level, potentially leading to full system compromise. The impact is primarily restricted to systems where the ABRT service is active and local users have sufficient permissions to initiate reporting processes. Organizations still running affected, legacy versions of RHEL or related distributions are at the highest risk.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eTransition away from end-of-life versions of the Red Hat Automatic Bug Reporting Tool as advised by the vendor and CISA.\u003c/li\u003e\n\u003cli\u003eEvaluate internet-facing assets for the presence of the vulnerable ABRT package and ensure patching or removal in accordance with CISA BOD 26-04.\u003c/li\u003e\n\u003cli\u003eConduct a forensics triage of assets identified as running legacy or vulnerable versions of ABRT following CISA guidance.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-26T20:17:10Z","date_published":"2026-08-26T20:17:10Z","id":"https://feed.craftedsignal.io/briefs/2026-08-abrt-priv-esc/","summary":"The Red Hat Automatic Bug Reporting Tool (ABRT) contains a local privilege escalation vulnerability (CVE-2015-5287) that allows unauthorized users to gain elevated access via symlink attacks.","title":"Local Privilege Escalation in Red Hat Automatic Bug Reporting Tool","url":"https://feed.craftedsignal.io/briefs/2026-08-abrt-priv-esc/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:redhat:automatic_bug_reporting_tool:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}