CVE-2021-25630
In the vulnerable version of "loolforkit" this check was wrong, so a normal user could start "loolforkit" and eventually get local root privileges.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.31%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
"loolforkit" is a privileged program that is supposed to be run by a special, non-privileged "lool" user. Before doing anything else "loolforkit" checks, if it was invoked by the "lool" user, and refuses to run with privileges, if it's not the case. In the vulnerable version of "loolforkit" this check was wrong, so a normal user could start "loolforkit" and eventually get local root privileges.
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.31% probability · 24th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-269
- Affected
- collaboraoffice/online
- Source
- security@documentfoundation.org
References
- https://github.com/CollaboraOnline/online/security/advisories/GHSA-49w3-gr3w-m68vThird Party Advisory
- https://www.openwall.com/lists/oss-security/2021/01/18/3Mailing List, Third Party Advisory
- https://github.com/CollaboraOnline/online/security/advisories/GHSA-49w3-gr3w-m68vThird Party Advisory
- https://www.openwall.com/lists/oss-security/2021/01/18/3Mailing List, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.