Local Privileges Elevation Vulnerability in X.Org
CVE-2022-46342

8.8HIGH

Key Information:

Vendor

X.org

Vendor
CVE Published:
14 December 2022

What is CVE-2022-46342?

A vulnerability exists in X.Org that may allow local users to elevate their privileges. This issue arises from the handling of the XvdiSelectVideoNotify request, which can lead to unintended writes to memory locations after they have been freed. If successfully exploited, attackers could gain unauthorized access and control over the affected systems, posing serious security concerns for users and administrators alike.

Affected Version(s)

xorg-x11-server xorg-x11-server-1.20.4

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.