CVE-2025-27591: Below: World Writable Dictory in /var/log/below Allows Local Privilege Escalation (CVE-2025-27591)

Published Mar 11, 2025
·
Updated

Impact A privilege escalation vulnerability existed in the Below service prior to v0.9.0 due to the creation of a world-writable directory at /var/log/below. This could have allowed local unprivileged users to escalate to root privileges through symlink attacks that manipulate files such as /etc/shadow.

Patches https://github.com/facebookincubator/below/commit/10e73a21d67baa2cd613ee92ce999cda145e1a83

This is included in version 0.9.0

Workarounds Change the permission on /var/log/below manually

References https://www.facebook.com/security/advisories/cve-2025-27591 https://www.cve.org/CVERecord?id=CVE-2025-27591

Affected Software

3 affected componentsFixes available
Below Below<0.9.0
rust/below<0.9.0
0.9.0
Facebook Below Rust<0.9.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade rust/below to a version that resolves this vulnerability.

    Fixed in 0.9.0
  2. Upgrade

    Upgrade Below to a version that resolves this vulnerability.

    Fixed in 0.9.0Patch CVE-2025-27591
  3. Configuration

    Manually change permissions on `/var/log/below` to remove world-writable access (the issue is a world-writable directory at `/var/log/below` that allowed symlink attacks against files such as `/etc/shadow`).

    Below (log directory permissions) /var/log/below permissions = not world-writable

Event History

Mar 11, 2025
CVE Published
via MITRE·06:29 PM
Data Sourced
via MITRE·06:29 PM
DescriptionWeakness
Data Sourced
via NVD·07:15 PM
DescriptionSeverity
Data Sourced
via NVD·07:15 PM
RemedyWeaknessAffected Software
Advisory Published
via GitHub·09:12 PM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-27591?

CVE-2025-27591 is classified as a medium severity privilege escalation vulnerability.

2

How do I fix CVE-2025-27591?

To fix CVE-2025-27591, upgrade Below to version 0.9.0 or later where the vulnerability has been resolved.

3

Who is affected by CVE-2025-27591?

CVE-2025-27591 affects users of Below versions prior to 0.9.0.

4

What type of attack does CVE-2025-27591 allow?

CVE-2025-27591 allows local unprivileged users to perform symlink attacks that could escalate privileges to root.

5

Where is the vulnerability located in CVE-2025-27591?

The vulnerability in CVE-2025-27591 is located in a world-writable directory created at /var/log/below.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203