• Home
  • About Us
  • Authors
  • Submit News
  • Contact Us
  • Privacy Policy
  • Sitemap
The Hack Post
  • Hacking News
    • Cyber Crime
  • Cyber Security
  • Technology
    • Internet
  • Entertainment
    • Gaming
  • Business
  • Science / Health
No Result
View All Result
The Hack Post
No Result
View All Result

NTFS-3G (Debian < 9) Vulnerable To Root Privilege Escalation: Local Root Exploit is Out

Connor Stewart by Connor Stewart
February 5, 2017
NTFS-3G (Debian < 9) Vulnerable To Root Privilege Escalation- Local Root Exploit is Out
Share on FacebookShare on Twitter

NTFS-3G (Debian < 9) local privilege escalation vulnerability (CVE-2017-0358) exploit has just been released to the public. The level of severity this exploit provides is extremely high due to the fact that hackers can be granted root access instantly. When the local root exploit is executed on a vulnerable server, the user will be given access to full control of the server, allowing them to not only just upload a malicious virus, but basically do whatever they like.

In response to the release of this exploit, Debian has officially released a patch taken control of the situation and problem. Issue solved right? Wrong. Many people will be ignorant and completely unaware of the exploit and patch, and therefore they may delay updating their Operating Systems and will leave them prone to attackers gaining root access on their systems.

A PoC by Kristian Erik Hermansen has also been released earlier today. The POC has been tested on a Debian 9 (Stretch) Operating System. As the Exploit is executed, it simply:

  • Gathers server environment information
  • Creates a kernel hijack directory
  • Creates a Symlink
  • Builds a Kernel Module
  • Grants you root access

According to Kristian Erik Hermansen, Debian 9 is not the only version of Debian to be vulnerable to the exploit. Debian 8 and Debian 7 along with Ubuntu, Gentoo and many other operating systems are vulnerable too. We advise anyone with the listed Operating Systems to install the patches and/or upgrade to the latest versions to avoid falling victim to this exploit.

Tags: Debian ExploitNTFS-3G Exploit
Connor Stewart

Connor Stewart

Connor is an Editor at The Hack Post.

Next Post
Harmony Day, Australian Government Website Hacked By South Sudan Hackers

Harmony Day, Australian Government Website Hacked By South Sudan Hackers

Latest Articles

Conceptual graphic illustrating data breach monitoring and exposure intelligence solutions for businesses
Cyber Security

HIBP Alternatives for Businesses: Moving From Breach Lookup to Exposure Intelligence

June 16, 2026
Modern gaming setup with dual monitors, ergonomic chair, LED lighting, and surround sound
Gaming

Tips for Creating a Gaming Setup for Optimal Immersion and Comfort

June 6, 2026
Advocacy for disability rights with support and resources led by Laurence Grigorov
Business

Laurence Grigorov: Supporting Advocacy Efforts That Safeguard Disability Rights

June 4, 2026
Cloud application security best practices illustration with shield and cloud icons
Cyber Security

CNAPP Best Practices: 6 Ways to Keep Cloud Applications Secure

June 4, 2026
Mobile game user interface illustrating backend technology and seamless gameplay experience
Gaming

From Login to Game Launch: The Tech Stack Behind Mobile Gameplay

June 4, 2026
Cybersecurity health check dashboard showing risk score for businesses in minutes
Cyber Security

Cybercy Group Launches Free Cybersecurity Health Check That Reveals a Business’s Risk Score in Under Two Minutes

May 31, 2026
Artificial intelligence analyzing code for improved software quality assurance testing
Business

How Large Language Models Are Transforming Software Quality Assurance

May 31, 2026
Group exercising in a sunny park with yoga mats and fitness equipment for outdoor health benefits
Business

Outdoor Fitness Activities for Better Health

May 24, 2026
Abstract representation of ethical guidelines and safety protocols in AI software development
Cyber Security

Gunnari Auvinen: Ethical Priorities and Safety Practices in AI Software Development

May 21, 2026
SOC 2 compliance software dashboard displaying security and compliance monitoring features
Cyber Security

SOC 2 Compliance Software Explained: Features, Benefits, and Use Cases

May 18, 2026
Person jogging in summer wearing lightweight clothing and drinking water to stay cool while exercising
Featured

4 Ways to Keep Cool While Exercising During Summer

May 10, 2026
Telegram chat interface displaying fraud alerts and scam warnings for online marketplace activity
Cyber Security

A Marketplace of Deception: Navigating Telegram Fraud Monitoring

May 10, 2026
  • Home
  • About Us
  • Authors
  • Submit News
  • Contact Us
  • Privacy Policy
  • Sitemap

The Hack Post © 2019

No Result
View All Result
  • Hacking News
    • Cyber Crime
  • Cyber Security
  • Technology
    • Internet
  • Entertainment
    • Gaming
  • Business
  • Science / Health

The Hack Post © 2019