Kloxo versions 6.1.12 and earlier contain two setuid root binaries—lxsuexec and lxrestart—that allow local privilege escalation from uid 48. The lxsuexec binary performs a uid check and permits execution of arbitrary commands as root if the invoking user matches uid 48. This flaw enables attackers with Apache-level access to escalate privileges to root without authentication.
Metrics
Affected Vendors & Products
References
History
Wed, 06 Aug 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 04 Aug 2025 09:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Lxcenter
Lxcenter kloxo |
|
Vendors & Products |
Lxcenter
Lxcenter kloxo |
Fri, 01 Aug 2025 21:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Kloxo versions 6.1.12 and earlier contain two setuid root binaries—lxsuexec and lxrestart—that allow local privilege escalation from uid 48. The lxsuexec binary performs a uid check and permits execution of arbitrary commands as root if the invoking user matches uid 48. This flaw enables attackers with Apache-level access to escalate privileges to root without authentication. | |
Title | Kloxo <= 6.1.12 Local Privilege Escalation | |
Weaknesses | CWE-269 | |
References |
|
|
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: VulnCheck
Published: 2025-08-01T20:42:02.320Z
Updated: 2025-08-06T13:58:30.060Z
Reserved: 2025-08-01T16:20:30.826Z
Link: CVE-2012-10022

Updated: 2025-08-06T13:58:19.936Z

Status : Awaiting Analysis
Published: 2025-08-01T21:15:25.773
Modified: 2025-08-06T14:15:34.613
Link: CVE-2012-10022

No data.