Native code execution via unsigned LD_PRELOAD library
Published Dec 3, 2024 · Updated Dec 3, 2024
Code-signing bypass in Lorex 2K Indoor Wi-Fi Security Camera firmware allows local users to execute arbitrary native code. The kernel permits LD_PRELOAD to load an attacker-written ELF shared object into a valid signed executable without enforcing its signature. Root-level OS command execution is required to write the library and launch the signed process; the flaw then enables native payloads such as a reverse shell.
Summary
What happened
Code-signing bypass in Lorex 2K Indoor Wi-Fi Security Camera firmware allows local users to execute arbitrary native code. The kernel permits LD_PRELOAD to load an attacker-written ELF shared object into a valid signed executable without enforcing its signature. Root-level OS command execution is required to write the library and launch the signed process; the flaw then enables native payloads such as a reverse shell.
The record
- CVE
- CVE-2024-52548
- Published
- Dec 3, 2024
- Updated
- Dec 3, 2024
- Vendor
- Lorex Technology Inc.
- Product
- 2K Indoor Wi-Fi Security Camera
- Classifications
- CWE-345, T1574.006
- Attack vector
- local
- Privileges
- admin
Timeline
How it unfolded
- Dec 3, 2024CVE publishedPublication date reported by the CVE source.
- Dec 3, 2024Record updatedLatest update available in the CVE record.
Exploitability
Present is not the same as exploitable
Compare your product and version with the public record. A matching version still requires validation against your environment.
Is a vulnerable build present?
Compare these published version ranges with your installed build and any vendor patches.
- Affected versionversion=0 <2.800.0000000.8.R.20241111
What conditions does exploitation require?
What is affected?
Published CVSS scores
CVSS describes severity. EPSS estimates exploitation probability.
Attacks
What attackers are doing with it
Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.
Weakness, pattern, technique
Public exploit references
- Rapid7 Lorex RCE exploit chainfunctional · demonstrated
Labels summarize the accepted research assessment. They do not indicate a test against your environment.
Reported exploitation
- Rapid7 Pwn2Own IoT 2024 Lorex RCE chainexploit chain
Technologies
Your stack
See the directory against your own environment.
Your stack
Check the software in your environment
Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.
Book a demo