CVE-2018-14665

MEDIUM EXPLOITED RANSOMWARE

xorg-x11-server <1.20.3 - Privilege Escalation

Title source: llm

Description

A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options when starting Xorg. X server allows unprivileged users with the ability to log in to the system via physical console to escalate their privileges and run arbitrary code under root privileges.

Exploits (14)

exploitdb WORKING POC VERIFIED
by Metasploit · rubylocalunix
https://www.exploit-db.com/exploits/47701
exploitdb WORKING POC VERIFIED
by Metasploit · rubylocalmultiple
https://www.exploit-db.com/exploits/45908
exploitdb WORKING POC
by Marco Ivaldi · bashlocalsolaris
https://www.exploit-db.com/exploits/46142
exploitdb WORKING POC
by 0xdono · perllocalaix
https://www.exploit-db.com/exploits/45938
exploitdb WORKING POC
by Marco Ivaldi · bashlocalmultiple
https://www.exploit-db.com/exploits/45922
exploitdb WORKING POC
by bolonobolo · pythonlocallinux
https://www.exploit-db.com/exploits/45832
exploitdb WORKING POC
by Marco Ivaldi · bashlocalopenbsd
https://www.exploit-db.com/exploits/45742
exploitdb WORKING POC
by Hacker Fantastic · textlocalmultiple
https://www.exploit-db.com/exploits/45697
nomisec WORKING POC 17 stars
by jas502n · local
https://github.com/jas502n/CVE-2018-14665
nomisec WORKING POC
by bolonobolo · poc
https://github.com/bolonobolo/CVE-2018-14665
vulncheck_xdb WORKING POC
local
https://github.com/0xdea/exploits
metasploit WORKING POC GOOD
by Narendra Shinde, Raptor - 0xdea, Aaron Ringo, bcoles · rubypocunix
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/local/xorg_x11_suid_server.rb
metasploit WORKING POC GOOD
by Narendra Shinde, Aaron Ringo · rubypoclinux
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/local/xorg_x11_suid_server_modulepath.rb
metasploit WORKING POC GREAT
by Narendra Shinde · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/aix/local/xorg_x11_server.rb

References (20)

Scores

CVSS v3 6.6
EPSS 0.0894
EPSS Percentile 92.6%
Attack Vector PHYSICAL
CVSS:3.0/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

VulnCheck KEV 2020-10-01
Ransomware Use Confirmed
CWE
CWE-863
Status published
Products (11)
canonical/ubuntu_linux 16.04
canonical/ubuntu_linux 18.04
canonical/ubuntu_linux 18.10
debian/debian_linux 9.0
redhat/enterprise_linux_desktop 7.0
redhat/enterprise_linux_server 7.0
redhat/enterprise_linux_server_aus 7.6
redhat/enterprise_linux_server_eus 7.6
redhat/enterprise_linux_server_tus 7.6
redhat/enterprise_linux_workstation 7.0
... and 1 more
Published Oct 25, 2018
Tracked Since Feb 18, 2026