vendor:
X Window System
by:
@0xdono
6.6
CVSS
MEDIUM
Privilege Escalation
264
CWE
Product Name: X Window System
Affected Version From: X Window System Version 7.1.1
Affected Version To: X Window System Version 7.1.5.32
Patch Exists: NO
Related CWE: CVE-2018-14665
CPE: a:x.org:x_window_system:7.1.1
Metasploit:
https://www.rapid7.com/db/vulnerabilities/oracle_linux-cve-2018-14665/, https://www.rapid7.com/db/vulnerabilities/debian-cve-2018-14665/, https://www.rapid7.com/db/vulnerabilities/huawei-euleros-2_0_sp2-cve-2018-14665/, https://www.rapid7.com/db/vulnerabilities/redhat_linux-cve-2018-14665/, https://www.rapid7.com/db/vulnerabilities/huawei-euleros-2_0_sp3-cve-2018-14665/, https://www.rapid7.com/db/vulnerabilities/ibm-aix-cve-2018-14665/, https://www.rapid7.com/db/vulnerabilities/huawei-euleros-2_0_sp5-cve-2018-14665/, https://www.rapid7.com/db/vulnerabilities/centos_linux-cve-2018-14665/, https://www.rapid7.com/db/vulnerabilities/alpine-linux-cve-2018-14665/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2018-14665/, https://www.rapid7.com/db/vulnerabilities/huawei-euleros-2_0_sp8-cve-2018-14665/, https://www.rapid7.com/db/vulnerabilities/ubuntu-cve-2018-14665/, https://www.rapid7.com/db/vulnerabilities/gentoo-linux-cve-2018-14665/, https://www.rapid7.com/db/vulnerabilities/oracle-solaris-cve-2018-14665/
Other Scripts:
N/A
Platforms Tested: AIX 7.1 (6.x to 7.x should be vulnerable)
2018
AIX Xorg X11 Server – Local Privilege Escalation
Incorrect command-line parameter validation in the Xorg X server can lead to privilege elevation and/or arbitrary files overwrite, when the X server is running with elevated privileges. The -logfile argument can be used to overwrite arbitrary files in the file system, due to incorrect checks in the parsing of the option. This is a port of the OpenBSD X11 Xorg exploit to run on AIX. It overwrites /etc/passwd in order to create a new user with root privileges.
Mitigation:
IBM has not yet released a patch as of 29/11/2018.