NA
CVSSv3

CVE-2025-27591

CVSSv4: NA | CVSSv3: NA | CVSSv2: NA | VMScore: NA | EPSS: 0.0002 | KEV: Not Included
Published: 11/03/2025 Updated: 12/03/2025

Vulnerability Summary

Local Privilege Escalation in Below Service via World-Writable Directory

A privilege escalation vulnerability existed in the Below service prior to v0.9.0 due to the creation of a world-writable directory at /var/log/below. This could have allowed local unprivileged users to escalate to root privileges through symlink attacks that manipulate files such as /etc/shadow.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

meta platforms, inc below

Mailing Lists

Hello list, this is a report about a local root exploit issue in Below We shared this report with the linux-distros mailing list on 2025-03-07 and suggested an embargo of 5 days, which ends today Please find the full report below We also offer a rendered version of this report on our blog [1] 1) Introduction =============== Below [2] is a to ...