ZDI-CAN-22678: ZDI-24-121: X.Org Server DeliverStateNotifyEvent Heap-based Buffer Overflow Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of X.Org Server. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2024-0229.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-22678?
The severity of ZDI-CAN-22678 is assigned a CVSS rating of 7.8, indicating a high level of risk.
How do I fix ZDI-CAN-22678?
To fix ZDI-CAN-22678, upgrade to the latest version of X.Org Server that addresses this privilege escalation vulnerability.
Who is affected by ZDI-CAN-22678?
ZDI-CAN-22678 impacts installations of X.Org Server that allow local attackers to escalate privileges.
What type of vulnerability is ZDI-CAN-22678?
ZDI-CAN-22678 is a privilege escalation vulnerability that requires local access to exploit.
What is required to exploit ZDI-CAN-22678?
An attacker must first obtain the ability to execute low-privileged code on the target system to exploit ZDI-CAN-22678.