CVE-2018-14665
HIGH 7.2EPSS 27.0%
A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options when starting Xorg. X server allows unprivileged users with the ability to log in to the system via physical console to escalate their privileges and run arbitrary code under root privileges.
- CVSS v3.0
- 6.6 MEDIUM
CVSS:3.0/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - CVSS v2.0
- 7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C - EPSS
- 27.04% chance of exploitation in the next 30 days, 98th percentile
- Published
- 2018-10-25
- Updated
- 2024-08-05
Proof-of-concept exploits (5)
- https://www.exploit-db.com/exploits/45697/
- https://www.exploit-db.com/exploits/45742/
- bolonobolo/CVE-2018-146650★ · 2019-03-22
- chorankates/Help1★ · 2023-01-07
- jas502n/CVE-2018-1466517★ · 2018-10-27
Metasploit modules (1)
ExploitDB entries (6)
- https://www.exploit-db.com/exploits/47701
- https://www.exploit-db.com/exploits/45908
- https://www.exploit-db.com/exploits/46142
- https://www.exploit-db.com/exploits/45938
- https://www.exploit-db.com/exploits/45922
- https://www.exploit-db.com/exploits/45832