CVE-2022-37706
HIGH 7.8EPSS 5.5%
enlightenment_sys in Enlightenment before 0.25.4 allows local users to gain privileges because it is setuid root, and the system library function mishandles pathnames that begin with a /dev/.. substring.
- CVSS v3.1
- 7.8 HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 7.8 HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - EPSS
- 5.53% chance of exploitation in the next 30 days, 92th percentile
- Published
- 2022-12-25
- Updated
- 2025-04-14
Proof-of-concept exploits (9)
- MaherAzzouzi/CVE-2022-37706-LPE-exploit322★ · 2022-09-19
- ECU-10525611-Xander/CVE-2022-377062★ · 2022-09-18
- KaoXx/CVE-2022-377061★ · 2024-09-10
- Rebick/CVEs_exploit0★ · 2026-05-13
- TACTICAL-HACK/CVE-2022-37706-SUID0★ · 2024-07-20
- d3ndr1t30x/CVE-2022-377061★ · 2024-12-10
- junnythemarksman/CVE-2022-377060★ · 2024-06-03
- sanan2004/CVE-2022-377060★ · 2024-08-18
- opensesamedoors/Ubuntu-22-LPE