CVE-2016-15045Exploit

LOWCVSS 8.5 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

A local privilege escalation vulnerability exists in lastore-daemon, the system package manager daemon used in Deepin Linux (developed by Wuhan Deepin Technology Co., Ltd.). In versions 0.9.53-1 (Deepin 15.5) and 0.9.66-1 (Deepin 15.7), the D-Bus configuration permits any user in the sudo group to invoke the InstallPackage method without password authentication. By default, the first user created on Deepin is in the sudo group. An attacker with shell access can craft a .deb package containing a malicious post-install script and use dbus-send to install it via lastore-daemon, resulting in arbitrary code execution as root.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-269CWE-306

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Threat summary

  • Public PoC and exploit tooling are both present
  • 1 mentions across 1 observed day

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-07-07: 1PoC Mentioned / Linked · 2026-07-07: 1Exploit Tool / Code · 2026-07-07: 107-07
Signal classification1 categories
Exploit
1100.0%
Full discourse1 post
  • Andre Gironda@AndreGironda
    Exploit

    @chrissanders88 Older dbus-targeting CVEs with exploits include CVE-2015-8612 as blueman_set_dhcp_handler_dbus_priv_esc , and /var/log/lastore/daemon.log CVE-2016-15045 exploit/linux/local/lastore_daemon_dbus_priv_esc

    Post summary

    The tweet cites two older D‑Bus related CVEs and explicitly references available exploit code for them, but provides no details on active exploitation or patches.

    0000060
    3.8K followersView on X

Explore more