CVE-2018-14665

medium

Description

A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options when starting Xorg. X server allows unprivileged users with the ability to log in to the system via physical console to escalate their privileges and run arbitrary code under root privileges.

From the Tenable Blog

Tweetable Exploit for X.org Server Local Privilege Escalation (CVE-2018-14665) Released
Tweetable Exploit for X.org Server Local Privilege Escalation (CVE-2018-14665) Released

Published: 2018-10-26

A researcher has published a local privilege escalation exploit that fits in a single tweet for xorg-x11-server. Vendors are rolling out fixes and mitigation advice. Background On October 25, a tweetable proof-of-concept (PoC) exploit for a newly discovered local privilege escalation (LPE) vulnerability in xorg-x11-server was released.

References

Details

Source: Mitre, NVD

Published: 2018-10-25

Updated: 2024-11-21

Risk Information

CVSS v2

Base Score: 7.2

Vector: CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C

Severity: High

CVSS v3

Base Score: 6.6

Vector: CVSS:3.0/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Severity: Medium

EPSS

EPSS: 0.07358