https://seclists.org/oss-sec/2025/q1/201: Below: World Writable Dictory in /var/log/below Allows Local Privilege Escalation (CVE-2025-27591)
Published Mar 12, 2025
·Updated
Affected Software
1 affected component
Below Below
Frequently Asked Questions
1
What is the severity of CVE-2025-27591?
CVE-2025-27591 is classified as a local privilege escalation vulnerability.
2
How do I fix CVE-2025-27591?
To fix CVE-2025-27591, change the permissions of the /var/log/below directory to prevent world write access.
3
What software is affected by CVE-2025-27591?
CVE-2025-27591 affects the Below software.
4
Can CVE-2025-27591 be exploited remotely?
No, CVE-2025-27591 requires local access for exploitation.
5
What is the impact of CVE-2025-27591?
The impact of CVE-2025-27591 is that it allows local users to escalate privileges to root.