Writeup: use CVE-2022-41544 where it fits the service, gain a shell, and escalate to root.