vendor:
Xorg Server
by:
Hacker House
6.6
CVSS
MEDIUM
Local Privilege Escalation
269
CWE
Product Name: Xorg Server
Affected Version From: 1.19.0
Affected Version To: 1.20.2
Patch Exists: Yes
Related CWE: CVE-2018-14665
CPE: a:xorg:xorg_server
Metasploit:
https://www.rapid7.com/db/vulnerabilities/oracle_linux-cve-2018-14665/, https://www.rapid7.com/db/vulnerabilities/debian-cve-2018-14665/, https://www.rapid7.com/db/vulnerabilities/huawei-euleros-2_0_sp2-cve-2018-14665/, https://www.rapid7.com/db/vulnerabilities/redhat_linux-cve-2018-14665/, https://www.rapid7.com/db/vulnerabilities/huawei-euleros-2_0_sp3-cve-2018-14665/, https://www.rapid7.com/db/vulnerabilities/ibm-aix-cve-2018-14665/, https://www.rapid7.com/db/vulnerabilities/huawei-euleros-2_0_sp5-cve-2018-14665/, https://www.rapid7.com/db/vulnerabilities/centos_linux-cve-2018-14665/, https://www.rapid7.com/db/vulnerabilities/alpine-linux-cve-2018-14665/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2018-14665/, https://www.rapid7.com/db/vulnerabilities/huawei-euleros-2_0_sp8-cve-2018-14665/, https://www.rapid7.com/db/vulnerabilities/ubuntu-cve-2018-14665/, https://www.rapid7.com/db/vulnerabilities/gentoo-linux-cve-2018-14665/, https://www.rapid7.com/db/vulnerabilities/oracle-solaris-cve-2018-14665/
Other Scripts:
N/A
Platforms Tested: OpenBSD 6.4-stable
2018
CVE-2018-14665 – a LPE exploit via http://X.org fits in a tweet
This exploit uses CVE-2018-14665 to overwrite files as root. It impacts Xorg 1.19.0 - 1.20.2 which ships setuid and vulnerable in default OpenBSD. The exploit uses a command line to cd to the /etc directory and then runs Xorg with a root user and password. After a few seconds, the Xorg process is killed and the user can then use the su command to gain root privileges.
Mitigation:
Upgrade to the latest version of Xorg and ensure that the setuid bit is not set.