discovered 03 Aug 2026
CVE-2020-28243
→ View on GitHubThe CVE-2020-28243 tool exploits a command injection vulnerability within SaltStack's Salt, allowing for privilege escalation on affected minions when the master executes the `restartcheck` command. Notable features include a straightforward exploit script (`exploit.sh`) for executing arbitrary commands, and the capability to utilize pre-compiled static binaries if gcc is unavailable on the target system. This tool targets SaltStack versions from 2016.3.0rc2 to 3002.2, requiring specific access permissions to function effectively.