Description
A vulnerability, which was classified as critical, has been found in exelban stats up to 2.11.21. This issue affects the function shouldAcceptNewConnection of the component XPC Service. The manipulation leads to command injection. It is possible to launch the attack on the local host. Upgrading to version 2.11.22 is able to address this issue. It is recommended to upgrade the affected component.
References (5)
Core 5
Core References
Release Notes patch
https://github.com/exelban/stats/releases/tag/v2.11.22
Permissions Required, VDB Entry vdb-entry
technical-description
https://vuldb.com/?id.291269
Permissions Required, VDB Entry signature
permissions-required
https://vuldb.com/?ctiid.291269
Permissions Required, VDB Entry third-party-advisory
https://vuldb.com/?submit.473229
Various Sources related
https://winslow1984.com/books/cve-collection/page/stats-v21122-local-privilege-escalation
Scores
CVSS v3
7.8
EPSS
0.0096
EPSS Percentile
57.0%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
total
Details
CWE
CWE-74
CWE-77
Status
published
Products (22)
exelban/stats
2.11.0
exelban/stats
2.11.1
exelban/stats
2.11.10
exelban/stats
2.11.11
exelban/stats
2.11.12
exelban/stats
2.11.13
exelban/stats
2.11.14
exelban/stats
2.11.15
exelban/stats
2.11.16
exelban/stats
2.11.17
... and 12 more
Published
Jan 12, 2025
Tracked Since
Feb 18, 2026