A privilege escalation vulnerability existed in the Below service prior to v0.9.0 due to the creation of a world-writable directory at /var/log/below. This could have allowed local unprivileged users to escalate to root privileges through symlink attacks that manipulate files such as /etc/shadow.
References
| Link | Resource |
|---|---|
| https://github.com/facebookincubator/below/commit/da9382e6e3e332fd2c3195e22f34977f83f0f1f3 | Patch |
| https://www.facebook.com/security/advisories/cve-2025-27591 | Patch Vendor Advisory |
| http://www.openwall.com/lists/oss-security/2025/03/12/1 | Exploit Mailing List |
Configurations
History
No history.
Information
Published : 2025-03-11 19:15
Updated : 2025-07-03 14:40
NVD link : CVE-2025-27591
Mitre link : CVE-2025-27591
CVE.ORG link : CVE-2025-27591
JSON object : View
Products Affected
- below
CWE
CWE-732
Incorrect Permission Assignment for Critical Resource
