Local Privilege Escalation Vulnerability in GStreamer by GStreamer Developers
CVE-2025-2759
7.8HIGH
What is CVE-2025-2759?
A local privilege escalation vulnerability exists in the GStreamer installer due to incorrect permissions assigned to folders. This flaw enables local attackers to escalate their privileges after executing low-privileged code on the target system. By exploiting this vulnerability, an attacker can execute arbitrary code with the privileges of the target user, which poses a significant security risk to affected installations.
Affected Version(s)
GStreamer 1.24.8
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
CVSS V3.0
Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published