CVE-2018-14665
A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options when starting Xorg. X server allows...
- Published
- Oct 25, 2018
- Updated
- Aug 5, 2024
- Assigning CNA
- redhat
- Evidence observed
- Oct 25, 2018
Primary CVSS
nvd · CVSS 2.0
AV:L/AC:L/Au:N/C:C/I:C/A:CHigh · next 30 days
- Percentile
- 99.0%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
Summary
A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options when starting Xorg. X server allows unprivileged users with the ability to log in to the system via physical console to escalate their privileges and run arbitrary code under root privileges.
Sources
12- exploitsExploit
Public exploit repository covering local privilege escalation, buffer overflows, and database exploits across Linux, Solaris, AIX, OpenBSD, Zyxel, Oracle, and MySQL.
Proof-of-concept exploit for CVE-2018-14665, a local privilege escalation in Xorg on Linux distributions, with analysis and PoC for Red Hat.
- CVE-2018-14665Exploit
Local privilege escalation exploit for CVE-2018-14665 targeting X.Org Server on OpenBSD and Linux. Provides a proof-of-concept script to gain root access via vulnerable Xorg parameters.
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.