CVE-2022-27052

HIGH

FreeFtpd <1.0.13 - Privilege Escalation

Title source: llm
STIX 2.1

Description

FreeFtpd version 1.0.13 and below contains an unquoted service path vulnerability which allows local users to launch processes with elevated privileges.

Scores

CVSS v3 7.8
EPSS 0.0004
EPSS Percentile 12.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-428
Status published
Products (1)
freesshd/freeftpd < 1.0.13
Published Mar 31, 2022
Tracked Since Feb 18, 2026