← Blog · · df00tech

CISA KEV Adds 2015 Red Hat ABRT Privilege Escalation Flaw (CVE-2015-5287)

breaking kev Red Hat CVE-2015-5287

CISA has added CVE-2015-5287, a privilege escalation vulnerability in Red Hat's Automatic Bug Reporting Tool (ABRT), to its Known Exploited Vulnerabilities (KEV) catalog. According to the advisory, ABRT is vulnerable to a symlink attack: a local user with certain permissions can exploit a predictably-named file to escalate privileges. CISA's KEV listing indicates the flaw is being actively exploited in the wild, though no ransomware association has been confirmed at this time.

Why It Matters

ABRT shipped by default on several Red Hat Enterprise Linux and Fedora releases, so any system that still has it installed and enabled is a candidate for local privilege escalation — an attacker who already has limited shell access could use this flaw to gain root. The affected product line is now end-of-life/end-of-service, meaning official patches may no longer be forthcoming for many deployments, which raises the stakes for organizations still running legacy Red Hat systems.

What Defenders Should Do

  • Inventory systems for the ABRT package (abrt, abrt-cli, related daemons) and determine whether it is installed, enabled, and reachable by local users.
  • Where ABRT is present on EoL/EoS systems, prioritize decommissioning or migrating to a supported OS version rather than relying on further patching.
  • If ABRT must remain in place temporarily, disable the service or restrict local access, and monitor for anomalous symlink creation or file operations in ABRT's working directories as a hunting angle.
  • Review privilege-escalation and local exploitation telemetry (EDR, auditd) for processes interacting with ABRT-related predictable file paths.

This is a same-day KEV addition and details are still developing — full technical exploitation specifics have not been independently verified here. For the underlying code-level context, see the referenced commit: github.com/abrt/abrt/commit/3c1b60cfa62d39e5fff5a53a5bc53dae189e740e.

Get new detections in your inbox

New ATT&CK coverage plus CISA KEV / CVE detection rules, roughly weekly. No spam, unsubscribe anytime.