CVE-2021-25630 Vulnerability Details

  /     /     /  

CVE-2021-25630 Metadata Quick Info

CVE Published: 23/02/2021 | CVE Updated: 16/09/2024 | CVE Year: 2021
Source: Document Fdn. | Vendor: Collabora Productivity | Product: Collabora Online
Status : PUBLISHED

CVE-2021-25630 Description

"loolforkit" is a privileged program that is supposed to be run by a special, non-privileged "lool" user. Before doing anything else "loolforkit" checks, if it was invoked by the "lool" user, and refuses to run with privileges, if it\'s not the case. In the vulnerable version of "loolforkit" this check was wrong, so a normal user could start "loolforkit" and eventually get local root privileges.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID:
CWE Name: "loolforkit" privileged program local root exploit
Source: Collabora Productivity

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).