ZDI-CAN-22744: ZDI-24-120: X.Org Server XISendDeviceHierarchyEvent Heap-based Buffer Overflow Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of X.Org Server. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2024-21885.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-22744?
The ZDI-CAN-22744 vulnerability has been assigned a CVSS rating of 7.8, indicating a high severity level.
How do I fix ZDI-CAN-22744?
To mitigate ZDI-CAN-22744, update the X.Org Server to the latest version provided by the vendor.
Who is affected by ZDI-CAN-22744?
ZDI-CAN-22744 affects installations of X.Org Server that are running vulnerable configurations.
What type of attack does ZDI-CAN-22744 allow?
ZDI-CAN-22744 allows local attackers to escalate their privileges on affected systems.
What prerequisites are needed to exploit ZDI-CAN-22744?
An attacker must first gain the ability to execute low-privileged code on the target system to exploit ZDI-CAN-22744.