This Metasploit module attempts to gain root privileges on systems running Serv-U FTP Server versions prior to 15.1.7. The Serv-U executable is setuid root, and uses ARGV[0] in a call to system(), without validation, when invoked with the -prepareinstallation flag, resulting in command execution with root privileges. This module has been tested successfully on Serv-U FTP Server version 15.1.6 (x64) on Debian 9.6 (x64).
741d912f9d81ee69caacd00759e742b27f2fbda4aa232a5b4199ceb2b7e3a311
Serv-U FTP Server version 15.1.6 suffers from a local privilege escalation vulnerability.
25bff5ba2be3edf9ed986bd39f8d9bd1ae0e31fb8515abafc5e1c68e32374b5b