CVE-2025-27591
11.03.2025, 19:15
A privilege escalation vulnerability existed in the Below service prior to v0.9.0 due to the creation of a world-writable directory at /var/log/below. This could have allowed local unprivileged users to escalate to root privileges through symlink attacks that manipulate files such as /etc/shadow.Enginsight
Vendor | Product | Version |
---|---|---|
below | 𝑥 < 0.9.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration