Vulnerability Description
A privilege escalation vulnerability existed in the Below service prior to v0.9.0 due to the creation of a world-writable directory at /var/log/below. This could have allowed local unprivileged users to escalate to root privileges through symlink attacks that manipulate files such as /etc/shadow.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Below | < 0.9.0 |
Related Weaknesses (CWE)
References
- https://github.com/facebookincubator/below/commit/da9382e6e3e332fd2c3195e22f3497Patch
- https://www.facebook.com/security/advisories/cve-2025-27591PatchVendor Advisory
- http://www.openwall.com/lists/oss-security/2025/03/12/1ExploitMailing List
FAQ
What is CVE-2025-27591?
CVE-2025-27591 is a vulnerability with a CVSS score of 6.8 (MEDIUM). A privilege escalation vulnerability existed in the Below service prior to v0.9.0 due to the creation of a world-writable directory at /var/log/below. This could have allowed local unprivileged users ...
How severe is CVE-2025-27591?
CVE-2025-27591 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-27591?
Check the references section above for vendor advisories and patch information. Affected products include: Facebook Below.