CVE-2018-14665 is a local privilege escalation vulnerability in xorg-x11-server before version 1.20.3. The flaw is caused by incorrect permission checks applied to the Xorg command-line options -modulepath and -logfile when the server starts. On affected systems, an unprivileged local user who can log in through the physical console can abuse these options to influence privileged Xorg startup behavior. Publicly described exploitation uses the -modulepath option to cause Xorg to load attacker-controlled code as an X11 module, resulting in arbitrary code execution in the context of the X server process. Where Xorg runs with root privileges, this yields execution as root.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
4 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (6 hidden).
This repository contains a single Metasploit module (modules/exploits/aix/local/xorg_x11_server.rb) that exploits a local privilege escalation vulnerability (CVE-2018-14665) in the Xorg X11 Server on IBM AIX systems (versions 6.1, 7.1, and 7.2). The exploit leverages improper permission checks in Xorg's '-modulepath' and '-logfile' options to overwrite /etc/passwd, creating a new root user ('wow'). The module then executes a payload (default: a Perl reverse shell) as root and restores the original /etc/passwd file. The exploit requires local access and the ability to write to a directory (default: /tmp). The code is written in Ruby and is designed to be used within the Metasploit framework. Key fingerprintable endpoints include /etc/passwd, /tmp, and /usr/bin/ksh. The exploit is operational, providing a working privilege escalation and payload execution path on vulnerable AIX systems.
This repository contains a single Metasploit module (modules/exploits/multi/local/xorg_x11_suid_server.rb) that exploits a local privilege escalation vulnerability (CVE-2018-14665) in the Xorg X11 server (versions 1.19.0 < 1.20.3) when installed as a SUID binary. The exploit abuses improper permission checks for the -modulepath and -logfile options, allowing an unprivileged user to overwrite /etc/crontab and schedule a payload to be executed as root via cron. The module is weaponized, supporting customizable Metasploit payloads (defaulting to a reverse shell), and includes cleanup routines to restore the crontab after exploitation. The exploit targets Linux and OpenBSD systems and requires the attacker to be able to start the Xorg server. The code is written in Ruby and is structured as a standard Metasploit local exploit module.
This repository contains a single Metasploit module (Ruby file) that exploits a local privilege escalation vulnerability (CVE-2018-14665) in the Xorg X11 server (versions 1.19.0 < 1.20.3) when run as a SUID binary. The exploit abuses improper permission checks for the -modulepath and -logfile options, allowing an unprivileged user to load a malicious shared object and execute arbitrary code as root. The module performs several checks: it verifies the presence and SUID status of the Xorg binary, checks the version, ensures the user has console authentication (on Linux/CentOS), and confirms the target is not already running Xorg. The exploit compiles a C shared object that sets UID/GID to 0 and executes a payload script or binary as root, which is written to a writable directory (default: /tmp). The payload is customizable via Metasploit and can provide a shell or other post-exploitation capabilities. The module is weaponized, allowing for easy payload customization and cleanup of artifacts. The only file in the repository is the Metasploit module itself, written in Ruby.
This repository contains a local privilege escalation exploit for CVE-2018-14665, targeting OpenBSD 6.3 and 6.4 systems running a vulnerable setuid Xorg (versions 1.19.0 - 1.20.2). The main exploit script, 'openbsd-0day-cve-2018-14665.sh', leverages improper handling of the '-logfile' parameter in Xorg to overwrite the system's /etc/master.passwd file with a known root password hash. This allows a local attacker with a user account and the ability to run 'su' to gain root access by using the password 'Password1'. The script also backs up the original password file as /etc/master.passwd.old. The repository includes a README.md with detailed background and usage instructions, and a push.sh script for git operations. The exploit is operational and provides a working privilege escalation method on unpatched systems.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A prior X.Org X server vulnerability mentioned for historical comparison; public exploit code is noted as available.
An older X.Org privilege escalation vulnerability referenced as historical background on the vendor's security history.
A local privilege escalation vulnerability in xorg-x11-server before 1.20.3 caused by incorrect permission checks on the Xorg -modulepath and -logfile options, allowing local users with physical console access to execute code as root.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.