// For flags

CVE-2021-25630

 

Severity Score

7.8
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

"loolforkit" is a privileged program that is supposed to be run by a special, non-privileged "lool" user. Before doing anything else "loolforkit" checks, if it was invoked by the "lool" user, and refuses to run with privileges, if it's not the case. In the vulnerable version of "loolforkit" this check was wrong, so a normal user could start "loolforkit" and eventually get local root privileges.

"loolforkit" es un programa privilegiado que se supone debe ser ejecutado por un usuario "lool" especial, sin privilegios. Antes de hacer cualquier otra cosa, "loolforkit" comprueba si fue invocado por el usuario "lool" y se niega a ejecutar con privilegios, si no es el caso. En la versión vulnerable de "loolforkit", esta comprobación era equivocada, por lo que un usuario normal podría iniciar "loolforkit" y eventualmente alcanzar privilegios de root local

*Credits: Thanks to Matthias Gerstner (SUSE) for raising the issue.
CVSS Scores
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Local
Attack Complexity
Low
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2021-01-19 CVE Reserved
  • 2021-02-23 CVE Published
  • 2023-03-08 EPSS Updated
  • 2024-09-16 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-269: Improper Privilege Management
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Collaboraoffice
Search vendor "Collaboraoffice"
Online
Search vendor "Collaboraoffice" for product "Online"
>= 4.2.0 < 4.2.13
Search vendor "Collaboraoffice" for product "Online" and version " >= 4.2.0 < 4.2.13"
-
Affected
Collaboraoffice
Search vendor "Collaboraoffice"
Online
Search vendor "Collaboraoffice" for product "Online"
>= 6.4.0 < 6.4.3
Search vendor "Collaboraoffice" for product "Online" and version " >= 6.4.0 < 6.4.3"
-
Affected