Part of Lyceum Intelligence — deep-research In Focus reports → · Lyceum Corpus — ask the documents →

[KEV] CVE-2015-5287 -- CVSS 0.0 Vulnerability Briefing

[KEV] CVE-2015-5287 | CVSS 0.0 (Low) | Exploit: Operational

What Is It

CVE-2015-5287 is a local privilege escalation vulnerability in Red Hat Automatic Bug Reporting Tool (ABRT) caused by unsafe handling of a predictably named file that can be targeted through a symbolic link.

Technical Detail

A local user with the required ABRT-related permissions may be able to create a symbolic link at the predictable file path before ABRT accesses it. This can cause the tool to write to or otherwise operate on an unintended file with elevated privileges. Successful exploitation can enable local privilege escalation on affected systems.

Exploitation Status

This vulnerability has operational exploit maturity, indicating that exploitation methods are practical for use in real-world operations rather than being limited to a proof of concept. CISA has confirmed active exploitation in the wild.

Who Is Targeting This

Reported (research-inferred): MOONSTONESLEET, GORGONGROUP, MUSTANGPANDA, LEVIATHAN, and LAZARUSGROUP. No ATTAX-verified threat actor attribution is available in the provided data.

What To Do

Patch affected Red Hat ABRT installations with the vendor-supported fix or upgrade to a supported operating system release. CISA added this vulnerability to the Known Exploited Vulnerabilities Catalog on August 26, 2026; organizations should patch by August 26, 2026, or apply mitigations. That deadline has passed as of August 27, 2026, so unpatched affected systems should be treated as overdue for remediation. Where a supported patch is unavailable because the product or platform is end-of-life or end-of-service, discontinue use or migrate to a supported version. Restrict local access and ABRT-related permissions to trusted users, review systems for unexpected symbolic links in ABRT temporary or working directories, and investigate suspicious file modifications performed by ABRT or other privileged processes.

All analysis →

Deep-research intelligence reports from Lyceum Intelligence — structured assessments with sourced claims and calibrated conclusions.

Browse Intelligence Reports →