CVE Database · CVE-2018-14665
CVSS v3.1
N/A
EPSS
27.04%
Published
Oct 25, 2018
Modified
Aug 29, 2025
Public PoC / Exploit (9)
All weaponized →Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options when starting Xorg. X server allows unprivileged users with the ability to log in to the system via physical console to escalate their privileges and run arbitrary code under root privileges.
Weaknesses (CWE)
Affected Products (11)
References (20)