Vulnerability Description
v2rayL 2.1.3 allows local users to achieve root access because /etc/v2rayL/add.sh and /etc/v2rayL/remove.sh are owned by a low-privileged user but execute as root via Sudo.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| V2Rayl Project | V2Rayl | 2.1.3 |
Related Weaknesses (CWE)
References
- https://gist.github.com/bash-c/6ac238e8b15e60c9105e8cb6b42ec43c#file-v2rayl-lpe-ExploitThird Party Advisory
- https://gist.github.com/bash-c/6ac238e8b15e60c9105e8cb6b42ec43c#file-v2rayl-lpe-ExploitThird Party Advisory
FAQ
What is CVE-2020-10588?
CVE-2020-10588 is a vulnerability with a CVSS score of 7.8 (HIGH). v2rayL 2.1.3 allows local users to achieve root access because /etc/v2rayL/add.sh and /etc/v2rayL/remove.sh are owned by a low-privileged user but execute as root via Sudo.
How severe is CVE-2020-10588?
CVE-2020-10588 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-10588?
Check the references section above for vendor advisories and patch information. Affected products include: V2Rayl Project V2Rayl.