VDB
CVE-2023-33865
CVE-2023-33865
PUBLISHED
CVSS 8.5 HIGH
RenderDoc before 1.27 allows local privilege escalation via a symlink attack. It relies on the /tmp/RenderDoc directory regardless of ownership.
EPSS 0.89% · 58.1th percentile
Risk Scores
CVSS 4.0
8.5
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
EPSS Score
0.89%
58.1th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a, n/a |
| renderdoc | renderdoc | 0, 0, 0 |
Timeline
- Jun 7, 2023 CVE Published
- Jun 8, 2023 PoC Published
- Jun 8, 2023 EPSS Score
- Jun 8, 2023 PoC Published
- Jul 14, 2023 EPSS Score
- Aug 20, 2023 EPSS Score
- Sep 25, 2023 EPSS Score
- Nov 1, 2023 EPSS Score
- Dec 7, 2023 EPSS Score
- Jan 12, 2024 EPSS Score
- Feb 18, 2024 EPSS Score
- Mar 25, 2024 EPSS Score
References
- GLSA-202311-10 advisory
- https://lists.debian.org/debian-lts-announce/2024/12/msg00008.html advisory
- https://lists.debian.org/debian-lts-announce/2023/07/msg00023.html advisory
- http://packetstormsecurity.com/files/172804/RenderDoc-1.26-Local-Privilege-Escalation-Remote-Code-Execution.html exploit
- https://renderdoc.org/ url
- https://www.qualys.com/2023/06/06/renderdoc/renderdoc.txt url
- 20230607 LPE and RCE in RenderDoc: CVE-2023-33865, CVE-2023-33864, CVE-2023-33863 mailing-list
- https://nvd.nist.gov/vuln/detail/CVE-2023-33865 advisory
- https://renderdoc.org url