Back to search
CVE-2012-10022
Published: Aug 1, 2025
Modified: May 15, 2026
PUBLISHED
Description
Kloxo versions 6.1.12 and earlier contain two setuid root binaries—lxsuexec and lxrestart—that allow local privilege escalation from uid 48. The lxsuexec binary performs a uid check and permits execution of arbitrary commands as root if the invoking user matches uid 48. This flaw enables attackers with Apache-level access to escalate privileges to root without authentication.
| Vendor | Product | Versions |
|---|---|---|
LxCenter | Kloxo | affected 0 - <= 6.1.12 |
Weaknesses (CWE)
References
https://web.archive.org/web/20121122063935/http://roothackers.net/showthread.php?tid=92
technical-description
exploit
https://kloxo.org/
product
https://www.vulncheck.com/advisories/kloxo-local-priv-esc
third-party-advisory
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now