Description

A privilege escalation vulnerability existed in the Below service prior to v0.9.0 due to the creation of a world-writable directory at /var/log/below. This could have allowed local unprivileged users to escalate to root privileges through symlink attacks that manipulate files such as /etc/shadow.

INFO

Published Date :

2025-03-11T18:29:21.569Z

Last Modified :

2025-03-21T20:38:10.292Z

Source :

facebook
AFFECTED PRODUCTS

The following products are affected by CVE-2025-27591 vulnerability.

Vendors Products
Facebook
  • Below

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact