Privilege escalation in X.org Server - CVE-2018-14665
Published: October 25, 2018 / Updated: June 17, 2021
Vulnerability details
The vulnerability allows a local user to gain elevated privileges on the target system.
The vulnerability exists due to improper handling of two command-line options, namely -logfile and -modulepath. A local user can specify a '-modulepath' argument with an insecure path to create, overwrite or delete any files with root privileges.
Affected software
Arch Linux
Gentoo Linux
Debian Linux
IBM AIX
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for Power
Opensuse
Fedora
xorg-server (Alpine package)
xorg-x11-server
Dynamic System Analysis (DSA) Preboot
How to mitigate CVE-2018-14665
xorg-server (Alpine package) - addressed in versions 1.19.5-r1, 1.19.6-r3
Dynamic System Analysis (DSA) Preboot - update to dsyte2z-9.65
xorg-x11-server - addressed in versions 1.19.6-10.fc28, 1.20.3-1.fc29
Links to Public Exploits and PoC-codes
- Exploit #6096 - Xorg X11 Server - SUID privilege escalation (Metasploit) (June 17, 2021)
- Exploit #6102 - xorg-x11-server < 1.20.1 - Local Privilege Escalation (June 17, 2021)
- Exploit #6105 - xorg-x11-server 1.20.3 - Privilege Escalation (June 17, 2021)
- Exploit #6106 - xorg-x11-server < 1.20.3 - Local Privilege Escalation (June 17, 2021)
- Exploit #6090 - xorg-x11-server < 1.20.3 (Solaris 11) - 'inittab Local Privilege Escalation (June 17, 2021)
- Exploit #6092 - Xorg X11 Server (AIX) - Local Privilege Escalation (June 17, 2021)
- Exploit #6093 - xorg-x11-server < 1.20.3 - 'modulepath' Local Privilege Escalation (June 17, 2021)
- Exploit #5838 - Xorg X11 Server - Local Privilege Escalation (Metasploit) (June 17, 2021)
- Exploit #1502 - Xorg X11 Server Local Privilege Escalation (March 18, 2020)
- Exploit #1507 - Xorg X11 Server SUID modulepath Privilege Escalation (March 18, 2020)
- Exploit #1542 - Xorg X11 Server SUID logfile Privilege Escalation (March 18, 2020)
External References
Related Security Bulletins
- Privilege escalation in X.org Server
- Debian update for xorg-server
- Arch Linux update for xorg-server
- Gentoo update for X.Org X Server
- OpenSUSE Linux update for xorg-x11-server
- Multiple vulnerabilities in IBM AIX
- Red Hat update for xorg-x11-server
- Privilege escalation in xorg-server (Alpine package)
- Multiple vulnerabilities in IBM Dynamic System Analysis (DSA) Preboot
- Fedora 29 update for xorg-x11-server
- Fedora 28 update for xorg-x11-server