peter bassill · operator
$ cve CVE-2018-14665 JSON

CVE-2018-14665 EXPLOIT

6.6
MEDIUM · CVSS 3.0 · EPSS 27% (pctl 98)

Patch early

A public exploit exists.

Description

A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options when starting Xorg. X server allows unprivileged users with the ability to log in to the system via physical console to escalate their privileges and run arbitrary code under root privileges.

Scoring

CVSS6.6 (MEDIUM, v3.0)
VectorCVSS:3.0/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS27.04% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-863
On CISA KEVno
Public exploityes
Published2018-10-25
Last modified2026-06-17

Affected (9)

VendorProduct
canonicalubuntu linux
debiandebian linux
redhatenterprise linux desktop
redhatenterprise linux server
redhatenterprise linux server aus
redhatenterprise linux server eus
redhatenterprise linux server tus
redhatenterprise linux workstation
x.orgx server

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD