Independent perspective. Actionable security.Know what matters · Reduce exposure

Vulnerability Assurance / Intelligence

Red Hat ABRT Local Privilege Escalation (CVE-2015-5287)

Catalog analysis: CISA added this entry on August 26, 2026. The entry reflects catalog information retrieved on August 31, 2026, not a snapshot archived on the inclusion date. This site’s publication date is shown separately. Check current vendor guidance before acting.

What the vulnerability is

CVE-2015-5287 is a privilege escalation vulnerability residing in the Red Hat Automatic Bug Reporting Tool (ABRT). The flaw allows local users who possess specific permissions to elevate their privileges. This is achieved through a symlink attack targeting a file with a predictable name, which can mislead the system into performing operations on an unintended target.

Exposure and applicability

This vulnerability applies to environments where the ABRT tool is installed and active. A critical factor for vulnerability management teams is that impacted versions of this product may be end-of-life (EoL) or end-of-service (EoS). Because the tool is an open-source component, it may be integrated into various proprietary implementations or third-party libraries beyond standard Red Hat distributions.

Exposure is limited to local users; however, the risk increases in multi-user environments where low-privileged accounts have access to the system. The applicability of this vulnerability depends on whether the specific version of ABRT in use remains susceptible to predictable filename symlink attacks.

Remediation priorities

Our analysis suggests prioritizing remediation based on the support status of the affected asset:

  1. Decommissioning EoL/EoS Assets: For systems running versions of ABRT that are no longer supported by the vendor, the most effective risk reduction is to discontinue use of the product entirely.
  2. Version Transition: Systems requiring bug reporting capabilities should be transitioned to a currently supported version of the tool where this vulnerability has been addressed.
  3. Vendor Mitigations: Where immediate decommissioning or upgrading is not feasible, administrators should apply specific mitigations provided by the vendor.

How to validate remediation

Verification must go beyond a simple version check, as the presence of a newer version does not inherently prove that the symlink attack vector has been neutralized in a specific environment.

To verify that exposure has been reduced, defenders should:
* Confirm Removal: Verify the ABRT package is completely removed from EoL systems.
* Validate Patch Application: Cross-reference installed versions against vendor-provided security advisories to ensure the specific fix for CVE-2015-5287 is present.
* Configuration Audit: If compensating controls are used, verify that permissions on predictable filenames have been hardened to prevent unauthorized symlink creation.

Limits and open questions

There is currently no confirmed data regarding whether this vulnerability is being utilized in active ransomware campaigns. Additionally, because ABRT may be embedded in various third-party products, identifying all affected assets requires a comprehensive software bill of materials (SBOM) or deep package inspection rather than relying solely on OS-level versioning.

Residual risk remains if the tool is kept in an EoL state with only partial mitigations applied, as these may not address all potential paths for local privilege escalation.

Source and editorial note

CVE-2015-5287: Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability · Source date: August 26, 2026 · Retrieved August 31, 2026.

Material facts are tied to the cited primary source. Recommendations are independent defensive analysis unless attributed to the source. Confirm consequential decisions against current authoritative guidance.

Request a Vulnerability Assessment

Turn security intelligence into action.

Discuss your exposure, priorities, and the evidence needed to validate the outcome.

Request a security assessment ↗

Turn security intelligence into action.

Understand exposure, prioritize the response, and define evidence for the outcome.

Request a Security Assessment