CVE-2025-50691 – MCSManager Root Privilege Escalation Vulnerability

The following table lists the changes that have been made to the
CVE-2025-50691 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by [email protected]

    Aug. 22, 2025

    Action Type Old Value New Value
    Added Description MCSManager 10.5.3 daemon process runs as a root account by default, and its sensitive data (including tokens and terminal content) is stored in the data directory, readable by all users. Other users on the system can read the daemon’s key and use it to log in, leading to privilege escalation.
    Added Reference https://github.com/bddjr/bddjr/discussions/9
    Added Reference https://github.com/MCSManager/MCSManager/pull/1596
Share the Post:

Related Posts