SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2018-14665

X server allows unprivileged users with the ability to log in to the system via physical console to escalate their privileges and run arbitrary code under root privileges.

MEDIUM 6.6EPSS 27.0%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 27.0%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.

Description

A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options when starting Xorg. X server allows unprivileged users with the ability to log in to the system via physical console to escalate their privileges and run arbitrary code under root privileges.

CVSS 3.0
6.6 MEDIUMCVSS:3.0/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS
27.04% probability · 98th percentile
CISA KEV
Not listed
Weakness
CWE-863
Affected
x.org/x server · redhat/enterprise linux desktop · redhat/enterprise linux server · redhat/enterprise linux server aus · redhat/enterprise linux server eus · redhat/enterprise linux server tus · redhat/enterprise linux workstation · canonical/ubuntu linux · debian/debian linux
Source
secalert@redhat.com

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.