CVE-2025-27591
HIGH 7.8EPSS 0.4%
A privilege escalation vulnerability existed in the Below service prior to v0.9.0 due to the creation of a world-writable directory at /var/log/below. This could have allowed local unprivileged users to escalate to root privileges through symlink attacks that manipulate files such as /etc/shadow.
- CVSS v4.0
- 7.3 HIGH
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N - CVSS v3.1
- 6.8 MEDIUM
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N - CVSS v3.1
- 7.8 HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - EPSS
- 0.36% chance of exploitation in the next 30 days, 29th percentile
- Published
- 2025-03-11
- Updated
- 2025-03-21
Proof-of-concept exploits (20)
- 00xCanelo/CVE-2025-275912★ · 2025-07-23
- BridgerAlderson/CVE-2025-27591-PoC32★ · 2025-07-16
- Cythonic1/CVE-2025-275913★ · 2025-07-31
- Diabl0xE/CVE-2025-275192★ · 2026-07-28
- HOEUN-Visai/CVE-2025-27591-below-2★ · 2025-09-03
- Thekin-ctrl/CVE-2025-27591-Below0★ · 2025-07-20
- alialucas7/CVE-2025-27591_PoC0★ · 2025-07-17
- avina5hr/Cyber-security0★ · 2025-07-15
- danil-koltsov/below-log-race-poc1★ · 2025-09-01
- dollarboysushil/Linux-Privilege-Escalation-CVE-2025-275917★ · 2025-07-15
- incommatose/CVE-2025-27591-PoC5★ · 2025-07-19
- obamalaolu/CVE-2025-2759113★ · 2025-07-12
- rvizx/CVE-2025-275913★ · 2025-11-16
- umutcamliyurt/CVE-2025-275911★ · 2026-05-21
- 0x00Jeff/CVE-2025-27591
- MoTechStore/CVE-2025-27591-PoC
- Stp1t/CVE-2025-27591
- VisaiCyber/CVE-2025-27591-below-
- krn966/CVE-2025-27591
- rvzsec/CVE-2025-27591