peter bassill · operator
$ cve CVE-2011-2921 JSON

CVE-2011-2921 EXPLOIT

9.8
CRITICAL · CVSS 3.1 · EPSS 83.1% (pctl 100)

Patch early

A public exploit exists.

Description

ktsuss versions 1.4 and prior has the uid set to root and does not drop privileges prior to executing user specified commands, which can result in command execution with root privileges.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS83.11% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-273
On CISA KEVno
Public exploityes
Published2019-11-19
Last modified2026-06-16

Affected (1)

VendorProduct
ktsuss projectktsuss

Public exploits

SourceTitleDate
exploit-dbktsuss 1.4 - suid Privilege Escalation (Metasploit)2019-09-03

References

→ the Explorer  ·  watch your stack  ·  NVD