ID:6105 - Exploit for Privilege escalation in X.org Server - CVE-2018-14665

 
Main Vulnerability Database Exploits ID:6105 - Exploit for Privilege escalation in X.org Server - CVE-2018-14665

ID:6105 - Exploit for Privilege escalation in X.org Server - CVE-2018-14665

Published: June 17, 2021


Vulnerability identifier: #VU15538
Vulnerability risk: Low
CVE-ID: CVE-2018-14665
CWE-ID: CWE-264
Exploitation vector: Local access
Vulnerable software:
X.org Server

Link to public exploit:


Vulnerability description

The vulnerability allows a local user to gain elevated privileges on the target system.

The vulnerability exists due to improper handling of two command-line options, namely -logfile and -modulepath. A local user can specify a '-modulepath' argument with an insecure path to create, overwrite or delete any files with root privileges.


Remediation

Update to version 1.20.3.