Back

HIGH

xorg-x11-server: local privilege escalation

Published May 26, 2021

Description

A privilege escalation flaw was found in the Xorg-x11-server due to a lack of authentication for X11 clients. This flaw allows an attacker to take control of an X application by impersonating the server it is expecting to connect to.

Affected products

Remediation

Red Hat statement

As per upstream, exploiting this flaw is non-trivial and it requires exact timing on the behalf of the attacker. Many graphical applications exit if their connection to the X server is lost, so a typical desktop session is either impossible or difficult to exploit. There is currently no upstream patch available for this flaw.

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published May 26, 2021
Updated Aug 4, 2024
Reserved Sep 16, 2020
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Nov 9, 2020
ENISA EUVD
Assigner redhat
Published May 26, 2021
Updated Aug 4, 2024
Exploited since n/a
EUVD-2020-18358