CVE-2023-1393
published 2023-03-30CVE-2023-1393: A flaw was found in X.Org Server Overlay Window. A Use-After-Free may lead to local privilege escalation. If a client explicitly destroys the compositor…
PriorityP342high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
ITW
Exploited in the wild
EPSS
0.44%
35.7th percentile
A flaw was found in X.Org Server Overlay Window. A Use-After-Free may lead to local privilege escalation. If a client explicitly destroys the compositor overlay window (aka COW), the Xserver would leave a dangling pointer to that window in the CompScreen structure, which will trigger a use-after-free later.
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | xorg-server | < xorg-server 2:21.1.7-2 (bookworm) | xorg-server 2:21.1.7-2 (bookworm) |
| debian | xwayland | < xorg-server 2:21.1.7-2 (bookworm) | xorg-server 2:21.1.7-2 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| msrc | azl3_xorg-x11-server_1.20.10-4_on_azure_linux_3.0 | — | — |
| msrc | azl3_xorg-x11-server_1.20.10-5_on_azure_linux_3.0 | — | — |
| msrc | azl3_xorg-x11-server_1.20.10-6_on_azure_linux_3.0 | — | — |
| msrc | azure_linux_3.0_arm | — | — |
| msrc | azure_linux_3.0_x64 | — | — |
| msrc | cbl2_xorg-x11-server_1.20.10-4_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| x.org | x_server | < 21.1.8 | 21.1.8 |
| x.org | xorg-server | >= 0 < 2:1.20.11-1+deb11u6 | 2:1.20.11-1+deb11u6 |
| x.org | xorg-server | >= 0 < 2:21.1.7-2 | 2:21.1.7-2 |
| x.org | xorg-server | >= 0 < 2:21.1.7-2 | 2:21.1.7-2 |
| x.org | xorg-server | >= 0 < 2:21.1.7-2 | 2:21.1.7-2 |
| x.org | xwayland | >= 0 < 2:22.1.9-1 | 2:22.1.9-1 |
| x.org | xwayland | >= 0 < 2:22.1.9-1 | 2:22.1.9-1 |
| x.org | xwayland | >= 0 < 2:22.1.9-1 | 2:22.1.9-1 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
cisa9.8CRITICAL
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_oracle7.8HIGH
vendor_redhat7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Liferay Portal Uses Default Password
ghsa·2025-09-15
CVE-2025-43799 [MEDIUM] CWE-1393 Liferay Portal Uses Default Password
Liferay Portal Uses Default Password
Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92 and 7.3 GA through update 35, and older unsupported versions does not limit access to APIs before a user has changed their initial password, which allows remote users to access and edit content via the API.
GHSA
GHSA-gvfw-3vr2-x46g: A flaw was found in X
ghsa_unreviewed·2023-03-30
CVE-2023-1393 [HIGH] CWE-416 GHSA-gvfw-3vr2-x46g: A flaw was found in X
A flaw was found in X.Org Server Overlay Window. A Use-After-Free may lead to local privilege escalation. If a client explicitly destroys the compositor overlay window (aka COW), the Xserver would leave a dangling pointer to that window in the CompScreen structure, which will trigger a use-after-free later.
OSV
CVE-2023-1393: A flaw was found in X
osv·2023-03-30·CVSS 7.8
CVE-2023-1393 [HIGH] CVE-2023-1393: A flaw was found in X
A flaw was found in X.Org Server Overlay Window. A Use-After-Free may lead to local privilege escalation. If a client explicitly destroys the compositor overlay window (aka COW), the Xserver would leave a dangling pointer to that window in the CompScreen structure, which will trigger a use-after-free later.
Oracle
Oracle Oracle JD Edwards Risk Matrix: E1 Dev Platform Tech - Cloud (X.Org Server) — CVE-2023-1393
vendor_oracle·2026-01-15·CVSS 7.8
CVE-2023-1393 [HIGH] Oracle Oracle JD Edwards Risk Matrix: E1 Dev Platform Tech - Cloud (X.Org Server) — CVE-2023-1393
Oracle Oracle JD Edwards Risk Matrix: E1 Dev Platform Tech - Cloud (X.Org Server) vulnerability
CVE: CVE-2023-1393
CVSS: 7.8
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpujan2026 (JAN 2026)
CISA
Acronis Cyber Infrastructure (ACI) Insecure Default Password Vulnerability
cisa·2024-07-29·CVSS 9.8
CVE-2023-45249 [CRITICAL] CWE-1393 Acronis Cyber Infrastructure (ACI) Insecure Default Password Vulnerability
Vulnerability: Acronis Cyber Infrastructure (ACI) Insecure Default Password Vulnerability
Affected: Acronis Cyber Infrastructure (ACI)
Acronis Cyber Infrastructure (ACI) allows an unauthenticated user to execute commands remotely due to the use of default passwords.
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Notes: https://security-advisory.acronis.com/advisories/SEC-6452; https://nvd.nist.gov/vuln/detail/CVE-2023-45249
Remediation Due Date: 2024-08-19
CISA ICS
Siemens SCALANCE XCM-/XRM-300
cisa_ics·2024-02-15
Siemens SCALANCE XCM-/XRM-300
ICS Advisory
##
Siemens SCALANCE XCM-/XRM-300
Release DateFebruary 15, 2024
Alert CodeICSA-24-046-11
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SCALANCE XCM-/XRM-300
- Vulnerabilities: Out-of-bounds Write, Incorrect Type Conversion or Cast, Improper Verification of Cryptographic Signature, Improper Access Control, Improper Authentication, Missing Encryption
Ubuntu
X.Org X Server vulnerability
vendor_ubuntu·2023-03-29
CVE-2023-1393 X.Org X Server vulnerability
Title: X.Org X Server vulnerability
Summary: X.Org X Server could be made to crash or run programs as the administrator
if it received specially crafted input.
Jan-Niklas Sohn discovered that the X.Org X Server incorrectly handled
certain memory operations. An attacker could possibly use these issues to
cause the X Server to crash, execute arbitrary code, or escalate
privileges.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Red Hat
xorg-x11-server: X.Org Server Overlay Window Use-After-Free Local Privilege Escalation Vulnerability
vendor_redhat·2023-03-29·CVSS 7.8
CVE-2023-1393 [HIGH] CWE-416 xorg-x11-server: X.Org Server Overlay Window Use-After-Free Local Privilege Escalation Vulnerability
xorg-x11-server: X.Org Server Overlay Window Use-After-Free Local Privilege Escalation Vulnerability
A flaw was found in X.Org Server Overlay Window. A Use-After-Free may lead to local privilege escalation. If a client explicitly destroys the compositor overlay window (aka COW), the Xserver would leave a dangling pointer to that window in the CompScreen structure, which will trigger a use-after-free later.
A vulnerability was found in X.Org Server. This flaw occurs if a client explicitly destroys the compositor overlay window (aka COW), where Xserver leaves a dangling pointer to that window in the CompScreen structure, which will later trigger a use-after-free issue. The Overlay Window use-after-free issue can lead to a local privilege escalation vulnerability.
Statement: Xorg server do
BSD
OpenBSD 7.1 Errata 028: SECURITY FIX
bsd_advisories·2023-03-29·CVSS 7.8
CVE-2023-1393 [HIGH] OpenBSD 7.1 Errata 028: SECURITY FIX
OpenBSD 7.1 Errata 028: SECURITY FIX
028: SECURITY FIX: March 29, 2023
All architectures Xserver, CVE-2023-1393: use after free bug in the Composite server extension.
BSD
OpenBSD 7.2 Errata 024: SECURITY FIX
bsd_advisories·2023-03-29·CVSS 7.8
CVE-2023-1393 [HIGH] OpenBSD 7.2 Errata 024: SECURITY FIX
OpenBSD 7.2 Errata 024: SECURITY FIX
024: SECURITY FIX: March 29, 2023
All architectures Xserver, CVE-2023-1393: use after free bug in the Composite server extension.
Microsoft
A flaw was found in X.Org Server Overlay Window. A Use-After-Free may lead to local privilege escalation. If a client explicitly destroys the compositor overlay window (aka COW) the Xserver would leav
vendor_msrc·2023-03-14·CVSS 7.8
CVE-2023-1393 [HIGH] CWE-416 A flaw was found in X.Org Server Overlay Window. A Use-After-Free may lead to local privilege escalation. If a client explicitly destroys the compositor overlay window (aka COW) the Xserver would leav
A flaw was found in X.Org Server Overlay Window. A Use-After-Free may lead to local privilege escalation. If a client explicitly destroys the compositor overlay window (aka COW) the Xserver would leave a dangling pointer to that window in the CompScreen structure which will trigger a use-after-free later.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. S
Debian
CVE-2023-1393: xorg-server - A flaw was found in X.Org Server Overlay Window. A Use-After-Free may lead to lo...
vendor_debian·2023·CVSS 7.8
CVE-2023-1393 [HIGH] CVE-2023-1393: xorg-server - A flaw was found in X.Org Server Overlay Window. A Use-After-Free may lead to lo...
A flaw was found in X.Org Server Overlay Window. A Use-After-Free may lead to local privilege escalation. If a client explicitly destroys the compositor overlay window (aka COW), the Xserver would leave a dangling pointer to that window in the CompScreen structure, which will trigger a use-after-free later.
Scope: local
bookworm: resolved (fixed in 2:21.1.7-2)
bullseye: resolved (fixed in 2:1.20.11-1+deb11u6)
forky: resolved (fixed in 2:21.1.7-2)
sid: resolved (fixed in 2:21.1.7-2)
trixie: resolved (fixed in 2:21.1.7-2)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://gitlab.freedesktop.org/xorg/xserver/-/commit/26ef545b3502f61ca722a7a3373507e88ef64110https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BPNQYHUI63DB5FHK6EOI3Z4C6YQZGZKI/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/H3EVO3OQV6T4BSABWZ2TU3PY5TJTEQZ2/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MEHSYYFGBN3G4RS2HJXKQ5NBMOAZ5F2F/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NOYATGGPMT3COC7ELAJW5TG2PVS3AFR2/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PSAAGI5V77FQXIT5PP4URP6BYQVCK5U5/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QHJMSMK7G4GPLMKIGKXIOL2RTKU5VFWE/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SW2NRC3V53PIBXFPFBVWCOM2MDDILWQS/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SWFUDSBSABRHQOX6TIQ5O3SNPFTPFQQP/https://security.gentoo.org/glsa/202305-30https://www.openwall.com/lists/oss-security/2023/03/29/1https://gitlab.freedesktop.org/xorg/xserver/-/commit/26ef545b3502f61ca722a7a3373507e88ef64110https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BPNQYHUI63DB5FHK6EOI3Z4C6YQZGZKI/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/H3EVO3OQV6T4BSABWZ2TU3PY5TJTEQZ2/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MEHSYYFGBN3G4RS2HJXKQ5NBMOAZ5F2F/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NOYATGGPMT3COC7ELAJW5TG2PVS3AFR2/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PSAAGI5V77FQXIT5PP4URP6BYQVCK5U5/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QHJMSMK7G4GPLMKIGKXIOL2RTKU5VFWE/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SW2NRC3V53PIBXFPFBVWCOM2MDDILWQS/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SWFUDSBSABRHQOX6TIQ5O3SNPFTPFQQP/https://security.gentoo.org/glsa/202305-30https://www.openwall.com/lists/oss-security/2023/03/29/1
2023-03-30
Published
Exploited in the wild