← volver
CVE-2012-10022highCWE-269

Kloxo <= 6.1.12 Local Privilege Escalation

36Vexday Risk Score

Corrige pronto. Ella tiene exploit funcional público.

ssvc Attendcvss 8.5epss 0.4%
de la publicación al arma0 días
Publicada en NVD1 ago
metasploit18 sept
probabilidad de explotación
0.4%top 72% de las CVE
explotación observada
noninguna fuente lo reporta
Kloxo versions 6.1.12 and earlier contain two setuid root binaries—lxsuexec and lxrestart—that allow local privilege escalation from uid 48. The lxsuexec binary performs a uid check and permits execution of arbitrary commands as root if the invoking user matches uid 48. This flaw enables attackers with Apache-level access to escalate privileges to root without authentication.
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Productos afectados
LxCenter · Kloxo