CVE-2025-27591 is a local privilege escalation vulnerability in the Below service prior to version 0.9.0. The issue stems from incorrect permission assignment on the log directory /var/log/below, which was created as world-writable. Because a privileged service writes through this attacker-influenced path, a local unprivileged user can abuse the directory with a symlink attack and redirect writes to arbitrary filesystem targets, including sensitive files such as /etc/shadow. This can result in unauthorized modification of root-owned files and subsequent elevation of privileges to root.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
19 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small local privilege escalation PoC for CVE-2025-27591 affecting Below on Linux. It contains two files: a README with usage notes and one Bash exploit script (`exp.sh`). The script removes any existing `error_root.log`, creates a symlink from `error_root.log` to `/etc/passwd`, and then runs `sudo below replay --time ...` with a crafted multiline argument containing a passwd-format account entry for user `tcg` with UID/GID 0 and `/bin/bash` as the shell. The apparent goal is to abuse Below's handling of error logging or file writes so that privileged output is redirected through the symlink into `/etc/passwd`. After the write, the script runs `su tcg` so the operator can log in using the known password corresponding to the embedded SHA-512 hash (`NewPassword123!` per the README). The exploit is clearly operational rather than a mere detector: it performs filesystem manipulation, invokes the vulnerable binary with a hardcoded payload, and attempts to obtain a root shell. No network communication or remote endpoints are present; the attack vector is strictly local.
This repository is a small standalone local privilege escalation exploit for CVE-2025-27591 affecting Meta Platforms' 'below' resource monitoring tool before version 0.9.0. The repo contains two files: a README describing the vulnerability, exploitation chain, prerequisites, and references; and a single Bash exploit script, exploit.sh, which is the operational entry point. The exploit abuses unsafe symlink handling in below's root error logging path. It deletes /var/log/below/error_root.log, replaces it with a symlink to /etc/passwd, and then runs 'sudo /usr/bin/below replay --time "invalid"' to force an error and trigger logging as root. According to the repository, below chmods and writes to the symlink target without validating that the path is not a symlink. After this, the script writes a passwordless UID 0 account entry ('rooted::0:0:root:/root:/bin/bash') through the symlinked log path and executes 'su rooted' to obtain a root shell. Main capability: local privilege escalation from a low-privileged user to root. There are no network callbacks or remote targets; the attack vector is purely local. The exploit is operational but simple: it uses hardcoded paths and a fixed payload targeting /etc/passwd. It is not a detection script and appears to be a genuine PoC/operational exploit rather than a framework module.
This repository is a small, focused local privilege-escalation PoC for CVE-2025-27591 affecting Below versions prior to 0.9.0 on Linux. The repository contains only two files: a README describing the vulnerability and a Bash exploit script (exploit.sh) that implements the attack. The exploit is not part of a larger framework. The script targets an insecure world-writable log directory at /var/log/below. It prepares a payload line for /etc/passwd that creates a passwordless UID 0 user named nikolas-trey, writes that line to /tmp/payload, verifies that /var/log/below is writable, removes any existing /var/log/below/error_root.log, and replaces that log file with a symlink to /etc/passwd. It then invokes sudo /usr/bin/below record to trigger the vulnerable logging behavior and finally appends the payload through the symlinked log path, thereby modifying /etc/passwd. If successful, the user can obtain root-equivalent access with su nikolas-trey. Structurally, the exploit is straightforward and operational rather than just demonstrative: it contains a main() routine, a helper run() wrapper around eval, hardcoded file paths, and a hardcoded payload. There is no remote communication, scanning, persistence, or modular payload support. The attack vector is purely local and relies on filesystem manipulation via symlink abuse. The main fingerprintable artifacts are the Below log directory and log file path, the target file /etc/passwd, the temporary payload file /tmp/payload, and the invoked binary /usr/bin/below.
Repository contains a single Bash exploit script (CVE-2025-27591.sh) and a README describing CVE-2025-27591 in the Linux tool Below (< v0.9.0). The exploit is a local privilege escalation via symlink attack: it leverages world-writable permissions on /var/log/below and /var/log/below/error_root.log created/used by a root-running Below service. The script checks that the attacker can run /usr/bin/below via sudo, backs up /etc/passwd to /tmp/passwd.bak, generates a SHA-512 password hash for a known password (rooted123), creates a malicious passwd entry for a new UID 0 user (root2), replaces /var/log/below/error_root.log with a symlink to /etc/passwd, triggers Below to write/recreate the log using `sudo /usr/bin/below replay --time "invalid"`, then overwrites the symlinked log path with the malicious passwd line—effectively modifying /etc/passwd. Finally it attempts `su root2` to obtain root-equivalent access. No network IOCs are present; all observables are local file paths and the sudo-invoked binary.
This repository contains a local privilege escalation exploit for CVE-2025-27591, targeting the 'Below' service (versions prior to 0.9.0) on Linux systems. The exploit leverages insecure file and directory permissions: the service creates a world-writable directory and log file, and will change the log file's permissions to 666 if they are not already set. The exploit removes the log file and replaces it with a symlink to /etc/passwd, then triggers the service to change the permissions of /etc/passwd to 666. Once /etc/passwd is world-writable, the exploit overwrites the root password entry to allow passwordless root login, and finally spawns a root shell. The repository consists of a single Python exploit script (exploit.py) and a README.md explaining the vulnerability and usage. The main attack vector is local, requiring the attacker to have access to the system. The exploit directly manipulates critical system files and is operational, providing a working privilege escalation path if the target is vulnerable.
This repository provides a local privilege escalation exploit for CVE-2025-27591, targeting the 'below' monitoring tool (versions <0.9.0) on Linux systems. The exploit leverages insecure creation of a world-writable log file by the 'below' program. The attack replaces the log file with a symlink to /etc/ld.so.preload, then triggers the vulnerable program to make /etc/ld.so.preload world-writable. The attacker writes the path to a malicious shared object (shared.so) into /etc/ld.so.preload, causing it to be loaded as root. The shared object spawns a reverse shell as root to 127.0.0.1:6969 and deletes traces of the exploit. The repository contains a Bash script to automate the attack (exploit.sh), a C source file for the shared object (shared.c), a compilation script (compile.sh), and a README with usage instructions and references. The exploit is operational and provides a root shell if successful, but requires local access and a vulnerable system configuration.
This repository contains a Bash exploit script (CVE-2025-27591) and a detailed README. The exploit targets a local privilege escalation vulnerability in the 'below' system performance monitoring tool (by Meta/Facebook), specifically when its log directory (/var/log/below) is world-writable. The script automates the process of creating a symlink from the log file (error_root.log) to /etc/passwd, then triggers the 'below' binary to write to this symlink, allowing the injection of a new root user entry. The exploit includes multiple fallback mechanisms for payload injection and robust error handling. The README provides comprehensive documentation, usage instructions, and mitigation advice. The main exploit file is 'CVE-2025-27591', written in Bash, and the attack vector is local privilege escalation via file system manipulation. No network endpoints are involved; all actions are performed locally on the target system.
This repository provides a proof-of-concept Bash exploit for CVE-2025-27591, a local privilege escalation vulnerability in the 'below' utility on Linux. The exploit leverages improper log file handling by 'below', allowing an attacker to symlink a log file under /var/log/below/ to /etc/passwd. The script repeatedly triggers the vulnerable binary and attempts to append a new root user entry ('root2', password '1') to /etc/passwd. If successful, the attacker can gain root shell access. The repository consists of a license, a README with detailed usage instructions, and a single Bash exploit script. The exploit requires local access and does not target remote systems.
This repository contains a Bash proof-of-concept exploit for CVE-2025-27591, a local privilege escalation vulnerability in the 'Below' service (versions prior to 0.9.0) on Linux. The exploit leverages a world-writable log directory (/var/log/below) to perform a symlink attack, redirecting a log file to /etc/passwd. By triggering the 'below' binary (typically run as root via sudo), the attacker can append a malicious user entry to /etc/passwd, effectively creating a new root user ('nemesis'). The repository consists of a README.md describing the vulnerability and a single exploit script (exploit.sh) that automates the attack steps. The exploit requires local access and a vulnerable configuration, and if successful, grants the attacker root shell access.
This repository contains a working exploit for CVE-2025-27591, targeting the 'below' tool on Linux systems. The exploit leverages insecure permissions on the application's log file, which is world-writable, to perform a symlink attack. The main exploit logic is implemented in 'main.c', which generates a hashed password, creates a symlink from /var/log/below/error_root.log to /etc/passwd, and then triggers the 'below' tool (assumed to be run as root) to log a crafted line that is a valid /etc/passwd entry. This results in the injection of a new root user with attacker-supplied credentials. The exploit requires the attacker to have the ability to run the 'below' tool as root (e.g., via sudo). The repository is structured simply, with a single C source file implementing the exploit, a README with usage instructions, and standard license and gitignore files. The main fingerprintable endpoints are the /etc/passwd file and the application's log file path.
This repository contains a local privilege escalation exploit for CVE-2025-27591, targeting the 'below' performance monitoring tool by Facebook on Linux systems. The exploit leverages a world-writable log directory (/var/log/below) and unsafe log file handling to perform a symlink attack. The Bash script (exploit.sh) checks for the vulnerability, creates a symlink from the application's log file to /etc/passwd, and triggers the vulnerable binary to write logs as root. It then appends a new root user entry to /etc/passwd, allowing the attacker to gain a root shell via 'su fakeadmin'. The repository consists of a detailed README.md explaining the vulnerability, exploitation steps, and prerequisites, and the exploit.sh script which automates the attack. The exploit requires local access, sudo privileges to run 'below record', and a misconfigured (world-writable) log directory. No network endpoints are involved; all actions are performed locally on the target system.
This repository contains a proof-of-concept (PoC) exploit for CVE-2025-27591, a local privilege escalation vulnerability in the 'below' system monitor tool on Linux. The exploit is implemented in a single Python script (Exploit.py) and leverages a symlink attack on the log file /var/log/below/error_root.log. By creating a symlink from this log file to /etc/passwd and then running the vulnerable 'below' binary with sudo, the script is able to append a new root-level user to /etc/passwd. If successful, it spawns a root shell as the injected user. The exploit requires local access and sudo privileges to run 'below record'. The repository also includes a README.md with detailed usage instructions and credits. No network endpoints are involved; all actions are performed locally on the target system.
This repository provides a proof-of-concept (PoC) exploit for CVE-2025-27591, a local privilege escalation vulnerability in the Below service (versions prior to v0.9.0) on Linux. The exploit leverages insecure permissions on the /var/log/below directory, which is world-writable, allowing a local attacker to replace a log file with a symlink to /etc/passwd. When the Below service is triggered with sudo, it overwrites /etc/passwd with attacker-controlled content, creating a new root user. The repository contains two files: a detailed README.md explaining the vulnerability, requirements, and usage, and a bash script (poc.sh) that automates the attack steps. The exploit requires local access and the ability to run 'sudo /usr/bin/below' without a password. No network endpoints are involved; all actions are performed locally via file system manipulation. The exploit is a functional PoC and demonstrates a classic symlink attack for privilege escalation.
This repository is a proof-of-concept (PoC) exploit for CVE-2025-27591, targeting the 'below' binary (by Facebook) on Linux systems. The exploit is implemented in Go (exploit.go) and is designed to be compiled and run locally on the target machine. The exploit checks if the /var/log/below directory is world-writable and then creates a symlink from /var/log/below/error_root.log to /etc/passwd. It writes a malicious passwd entry for a new root user ('attacker') and triggers the 'below' binary (via 'sudo below record') to cause the system to write to the symlinked log file, thereby appending the attacker's entry to /etc/passwd. If successful, the exploit spawns a root shell as the new user. The repository contains a README with build and usage instructions, as well as references to the CVE and related resources. The main attack vector is local privilege escalation via a symlink attack on a world-writable log directory.
This repository provides a proof-of-concept (PoC) exploit for CVE-2025-27591, a local privilege escalation vulnerability in the 'Below' service (versions prior to 0.9.0) on Linux systems. The vulnerability arises from the creation of the /var/log/below directory with world-writable permissions (0777), allowing a low-privilege user to create a symbolic link (symlink) in that directory pointing to a sensitive file such as /etc/passwd. When Below is executed as root (e.g., via sudo), it writes logs to the symlink, overwriting the target file. The provided Bash script (cve-2025-27591.sh) automates this attack: it removes any existing log file, creates a symlink from the log file to /etc/passwd, runs Below as root to trigger the log write, appends a new root user entry to /etc/passwd, and then attempts to switch to the new root user. The repository consists of a detailed README (in Spanish) explaining the vulnerability, exploitation steps, and mitigation, and a single Bash exploit script. The exploit is operational and demonstrates a real privilege escalation scenario, but is not weaponized for mass exploitation.
This repository contains a working exploit for CVE-2025-27591, a local privilege escalation vulnerability in the 'below' Linux system monitoring tool (versions prior to v0.9.0). The exploit leverages a world-writable log directory (/var/log/below) and the ability to run 'below' with sudo to perform a symlink attack. By replacing the log file with a symlink to /etc/passwd, the attacker can append a new root user entry, granting root shell access without a password. The repository consists of a detailed README.md explaining the vulnerability, manual exploitation steps, and a Python script (dbs_exploit.py) that automates the attack. The exploit is operational and requires specific system misconfigurations (world-writable log directory and sudo access to 'below'). Key fingerprintable endpoints include the log directory, log file, /etc/passwd, and the payload file. The exploit does not belong to a framework and is a standalone proof-of-concept with a functional payload.
This repository provides a proof-of-concept exploit for CVE-2025-27591, a local privilege escalation vulnerability in the 'Below' service (before version 0.9.0) by Facebook. The vulnerability arises from the creation of a world-writable log directory at /var/log/below, which allows an attacker to perform a symlink attack. The exploit script (exploit.py) checks for the vulnerability, creates a symlink from the log file to /etc/passwd, and then triggers the 'below' binary to write to the log file as root. It then appends a malicious line to /etc/passwd, creating a new root user ('attacker'), and attempts to spawn a root shell using this account. The repository consists of a README.md (explaining the vulnerability, exploitation steps, and references) and the exploit.py script (the main exploit logic). The exploit requires local access and does not target remote systems. The main fingerprintable endpoints are the file paths involved in the attack: /var/log/below, /var/log/below/error_root.log, /etc/passwd, /tmp/attacker, and /usr/bin/below.
This repository provides a local privilege escalation exploit for CVE-2025-27591, targeting the 'below' Linux monitoring tool (prior to v0.9.0). The exploit is implemented as a Bash script (CVE-2025-27591.sh) and leverages a symlink vulnerability in the way 'below' creates its log files as root. By symlinking /var/log/below/error_root.log to /etc/passwd and triggering 'below' to write to the log, the script overwrites /etc/passwd with a new root user ('haxor' with password 'hacked123'). The exploit requires that the attacker can run 'below' as root via sudo. The repository also includes a README.md with detailed vulnerability and usage information, and a standard GPLv3 LICENSE file. The main exploit file is self-contained and operational, demonstrating a real-world privilege escalation scenario on vulnerable systems.
This repository provides a proof-of-concept (PoC) exploit for CVE-2025-27591, a local privilege escalation vulnerability in Below <= v0.8.1 on Linux systems. The exploit leverages a world-writable log directory and insecure file permission handling in the 'below' binary. By symlinking a user-specific log file to /etc/passwd and triggering a log write via 'sudo /usr/bin/below snapshot', the attacker can append a new root user to the system password file. The exploit is implemented as a concise bash script (exploit.sh) that automates the attack steps: removing any existing log file, creating the malicious symlink, running the vulnerable binary with sudo, injecting a root user, and spawning a root shell. The repository consists of two files: a detailed README.md explaining the vulnerability, usage, and environment, and the exploit.sh script containing the exploit logic. The attack is local and requires the attacker to have sudo NOPASSWD access to the 'below' binary. Key fingerprintable endpoints include the log directory, the log file, the system password file, and the 'below' binary path.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
3 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.