Local Privileges Elevation Vulnerability in X.Org Affects Remote Code Execution
CVE-2022-46341

8.8HIGH

Key Information:

Vendor

X.org

Vendor
CVE Published:
14 December 2022

What is CVE-2022-46341?

A vulnerability in X.Org arises from an out-of-bounds memory access that occurs when the XIPassiveUngrab request is invoked with an unusually high keycode or button code. This flaw can allow local users to escalate their privileges on systems where the X server operates with elevated permissions and could permit remote code execution through SSH X forwarding sessions.

Affected Version(s)

xorg-x11-server xorg-x11-server-1.20.4

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.