CVE-2025-27591 – Below Privilege Escalation Vulnerability

The following table lists the changes that have been made to the
CVE-2025-27591 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by [email protected]

    Mar. 11, 2025

    Action Type Old Value New Value
    Added Description A privilege escalation vulnerability existed in the Below service prior to v0.9.0 due to the creation of a world-writable directory at /var/log/below. This could have allowed local unprivileged users to escalate to root privileges through symlink attacks that manipulate files such as /etc/shadow.
    Added Reference https://github.com/facebookincubator/below/commit/da9382e6e3e332fd2c3195e22f34977f83f0f1f3
    Added Reference https://www.facebook.com/security/advisories/cve-2025-27591
Share the Post:

Related Posts