CVE-2018-14665 describes a privilege escalation flaw in xorg-x11-server versions prior to 1.20.3, impacting Canonical, Debian, Red Hat, and X.Org distributions. This vulnerability allows unprivileged users with physical console access to execute arbitrary code with root privileges due to incorrect permission checks on the -modulepath and -logfile options. With a CVSS score of 6.6 (MEDIUM), it requires physical access and low privileges but can lead to full compromise (confidentiality, integrity, availability). While not listed in CISA's KEV catalog, multiple Metasploit modules and ExploitDB entries confirm readily available exploit code, and it has garnered significant community discussion and media coverage, indicating active awareness and potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.20.3CPE matchmatch criteria | cpe:2.3:a:x.org:x_server:*:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:* | ||
7.6CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_server_aus:7.6:*:*:*:*:*:*:* | ||
7.6CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_server_eus:7.6:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.