V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2018-14665
AST
MediumConfirmedExploit available

A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options when starting Xorg. X…

CVSS
6.6
Medium
EPSS
0.27
p97
Published
2018-01-01
Updated
2018-01-01
Description

A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options when starting Xorg. X server allows unprivileged users with the ability to log in to the system via physical console to escalate their privileges and run arbitrary code under root privileges.

Tags · CWE
CWE-271
CWE-863
Affected products
Debian_linux
CVSS vector
CVSS:3.0/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Timeline
2018-01-01
Published
2018-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: P
Physical (P)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: L
Low (L)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.270 · p97
Known exploited (KEV)
No
Known exploits — Сканер-ВС
45697
exploitdb · https://www.exploit-db.com/exploits/45697
Enterprise
45742
exploitdb · https://www.exploit-db.com/exploits/45742
Enterprise
45832
exploitdb · https://www.exploit-db.com/exploits/45832
Enterprise
45908
exploitdb · https://www.exploit-db.com/exploits/45908
Enterprise
45922
exploitdb · https://www.exploit-db.com/exploits/45922
Enterprise
45938
exploitdb · https://www.exploit-db.com/exploits/45938
Enterprise
46142
exploitdb · https://www.exploit-db.com/exploits/46142
Enterprise
47701
exploitdb · https://www.exploit-db.com/exploits/47701
Enterprise
CVE-2018-14665
github-poc · https://github.com/bolonobolo/CVE-2018-14665
Enterprise
Affected products
ProductVendorStatus
xorgTracked
xorgTracked
xorgTracked
xorgTracked
xorg-hwe-16.04Tracked
xorg-serverTracked
xorg-serverTracked
xorg-serverTracked
xorg-serverTracked
xorg-serverTracked
xorg-serverTracked
xorg-serverTracked
xorg-serverTracked
xorg-server-hwe-16.04Tracked
xorg-server-lts-utopicTracked
xorg-server-lts-vividTracked
xorg-server-lts-wilyTracked
xorg-server-lts-xenialTracked
xorg-x11-serverTracked
debian_linux*Tracked
Showing first 20 of 28
Source databases
AST
DEB
CVE
RED
UBU
Related vulnerabilities