Aller au contenu

Fiche vulnérabilité

CVE-2021-25630 : faille élevée collaboraoffice online (CVSS 7.8)

Description

"loolforkit" is a privileged program that is supposed to be run by a special, non-privileged "lool" user. Before doing anything else "loolforkit" checks, if it was invoked by the "lool" user, and refuses to run with privileges, if it's not the case. In the vulnerable version of "loolforkit" this check was wrong, so a normal user could start "loolforkit" and eventually get local root privileges.

En bref

Sévérité
Élevée (CVSS 7.8)
Vecteur CVSS
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
23 févr. 2021
Dernière mise à jour
17 juin 2026

Produits concernés

  • collaboraoffice online

Références

Rechercher une autre vulnérabilité dans la base CVE