CVE-1999-0526 describes a vulnerability where an X server's access control is disabled, typically via the 'xhost +' command, which allows any remote user to connect to the X server. This exposes the server to unauthorized access, as any user can open windows, capture keystrokes, or otherwise interact with the X session.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository contains a single Metasploit module: 'x11_keyboard_exec.rb', which targets open X11 servers on Unix systems. The exploit works by connecting to the X11 server over TCP (default port 6000), registering a virtual keyboard, and simulating keystrokes to open a terminal (xterm or gnome-terminal) on the target system. It then types and executes an arbitrary command payload, which can be any shell command supported by Metasploit's payload system. The exploit is weaponized, as it is part of the Metasploit framework and supports customizable payloads. The main attack vector is network-based, requiring the X11 service to be exposed and unauthenticated. The exploit targets systems vulnerable to CVE-1999-0526 (open X11 server). The code is written in Ruby and is structured as a standard Metasploit module.
This repository contains a single Metasploit auxiliary module: 'modules/auxiliary/gather/x11_keyboard_spy.rb'. The module implements a keylogger for X11 servers, inspired by the classic 'xspy' tool. It connects to a remote X11 server (typically on TCP port 6000), creates a background window, binds to the keyboard, and logs keystrokes. The module is operational and can be used to capture keystrokes from any X11 server that is accessible over the network and does not require authentication. The exploit targets the well-known X11 exposure issue (CVE-1999-0526), where X11 servers are left open to the network, allowing attackers to eavesdrop on user input. The module is written in Ruby and is designed to be run within the Metasploit Framework. The only file in the repository is the exploit module itself, and it contains all the logic for connecting, polling for keystrokes, filtering repeated keys, and storing the captured data as loot. No hardcoded IP addresses or domains are present, but the module targets the X11 service on TCP port 6000.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.