CVE-2025-23395
published 2025-05-26CVE-2025-23395: Screen 5.0.0 when it runs with setuid-root privileges does not drop privileges while operating on a user supplied path. This allows unprivileged users to…
PriorityP347high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.20%
10.1th percentile
Screen 5.0.0 when it runs with setuid-root privileges does not drop privileges while operating on a user supplied path. This allows unprivileged users to create files in arbitrary locations with `root` ownership, the invoking user's (real) group ownership and file mode 0644. All data written to the Screen PTY will be logged into this file, allowing to escalate to root privileges
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | screen | — | — |
| gnu | screen | >= 0 < 5.0.1-r0 | 5.0.1-r0 |
| gnu | screen | >= 0 < 5.0.1-r0 | 5.0.1-r0 |
| gnu | screen | >= 0 < 5.0.1-r0 | 5.0.1-r0 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv4.07.3HIGHCVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
osv7.3HIGH
vendor_debian7.3LOW
vendor_redhat7.3HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-84g7-x869-xfgv: Screen 5
ghsa_unreviewed·2025-05-26
CVE-2025-23395 [HIGH] CWE-271 GHSA-84g7-x869-xfgv: Screen 5
Screen 5.0.0 when it runs with setuid-root privileges does not drop privileges while operating on a user supplied path. This allows unprivileged users to create files in arbitrary locations with `root` ownership, the invoking user's (real) group ownership and file mode 0644. All data written to the Screen PTY will be logged into this file, allowing to escalate to root privileges
OSV
CVE-2025-23395: Screen 5
osv·2025-05-26·CVSS 7.3
CVE-2025-23395 [HIGH] CVE-2025-23395: Screen 5
Screen 5.0.0 when it runs with setuid-root privileges does not drop privileges while operating on a user supplied path. This allows unprivileged users to create files in arbitrary locations with `root` ownership, the invoking user's (real) group ownership and file mode 0644. All data written to the Screen PTY will be logged into this file, allowing to escalate to root privileges
Red Hat
screen: Local Root Exploit via `logfile_reopen()`
vendor_redhat·2025-05-13·CVSS 7.3
CVE-2025-23395 [HIGH] CWE-250 screen: Local Root Exploit via `logfile_reopen()`
screen: Local Root Exploit via `logfile_reopen()`
Screen 5.0.0 when it runs with setuid-root privileges does not drop privileges while operating on a user supplied path. This allows unprivileged users to create files in arbitrary locations with `root` ownership, the invoking user's (real) group ownership and file mode 0644. All data written to the Screen PTY will be logged into this file, allowing to escalate to root privileges
A flaw was found in Screen. When running with setuid-root privileged, the logfile_reopen() function does not drop privileges while operating on a user-supplied path. This vulnerability allows an unprivileged user to create files in arbitrary locations with root ownership.
Statement: This vulnerability only affects Screen versions 5.0.0 and above.
This is a modera
Debian
CVE-2025-23395: screen - Screen 5.0.0 when it runs with setuid-root privileges does not drop privileges w...
vendor_debian·2025·CVSS 7.3
CVE-2025-23395 [HIGH] CVE-2025-23395: screen - Screen 5.0.0 when it runs with setuid-root privileges does not drop privileges w...
Screen 5.0.0 when it runs with setuid-root privileges does not drop privileges while operating on a user supplied path. This allows unprivileged users to create files in arbitrary locations with `root` ownership, the invoking user's (real) group ownership and file mode 0644. All data written to the Screen PTY will be logged into this file, allowing to escalate to root privileges
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-05-26
Published