VulnerabilityModified
CVE-2011-2921
ktsuss versions 1.4 and prior has the uid set to root and does not drop privileges prior to executing user specified commands, which can result in command execution with root privileges.
CRITICAL 9.8EPSS 83.1%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 83.1%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.
Description
ktsuss versions 1.4 and prior has the uid set to root and does not drop privileges prior to executing user specified commands, which can result in command execution with root privileges.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 83.11% probability · 100th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-273
- Affected
- ktsuss project/ktsuss
- Source
- secalert@redhat.com
References
- http://packetstormsecurity.com/files/154307/ktsuss-Suid-Privilege-Escalation.htmlExploit, Third Party Advisory, VDB Entry
- https://access.redhat.com/security/cve/cve-2011-2921Broken Link, Third Party Advisory
- https://security-tracker.debian.org/tracker/CVE-2011-2921Third Party Advisory
- http://packetstormsecurity.com/files/154307/ktsuss-Suid-Privilege-Escalation.htmlExploit, Third Party Advisory, VDB Entry
- https://access.redhat.com/security/cve/cve-2011-2921Broken Link, Third Party Advisory
- https://security-tracker.debian.org/tracker/CVE-2011-2921Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.