← back
CVE-2012-10022highCWE-269

Kloxo <= 6.1.12 Local Privilege Escalation

36Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendcvss 8.5epss 0.4%
from disclosure to weapon0 days
Published on NVDAug 1
metasploitSep 18
exploitation probability
0.4%top 72% of all CVEs
observed exploitation
nono source reports it
Kloxo versions 6.1.12 and earlier contain two setuid root binaries—lxsuexec and lxrestart—that allow local privilege escalation from uid 48. The lxsuexec binary performs a uid check and permits execution of arbitrary commands as root if the invoking user matches uid 48. This flaw enables attackers with Apache-level access to escalate privileges to root without authentication.
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected products
LxCenter · Kloxo