Execution with Unnecessary Privileges Vulnerability in LightDM KDE Greeter by SUSE
CVE-2025-62876

5.3MEDIUM

Key Information:

Vendor

Suse

Status
Vendor
CVE Published:
12 November 2025

What is CVE-2025-62876?

A vulnerability in the LightDM KDE Greeter allows an attacker to escalate privileges from the service user to root, potentially compromising system security. This issue specifically affects versions prior to 6.0.4. Users of the affected versions must upgrade to mitigate the risk of unauthorized access and control.

Affected Version(s)

openSUSE ? < 6.0.4

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Matthias Gerstner of SUSE
.
CVE-2025-62876 : Execution with Unnecessary Privileges Vulnerability in LightDM KDE Greeter by SUSE