VDB
CVE-2025-53391
CVE-2025-53391
PUBLISHED
CVSS 9.300000190734863 CRITICAL
The Debian zuluPolkit/CMakeLists.txt file for zuluCrypt through the zulucrypt_6.2.0-1 package has insecure PolicyKit allow_any/allow_inactive/allow_active settings that allow a local user to escalate their privileges to root.
EPSS 0.15% · 4.7th percentile
Risk Scores
CVSS 3.1
9.300000190734863
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS Score
0.15%
4.7th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Debian | zulucrypt | zulucrypt_5.5.0-1 |
Timeline
- Jun 28, 2025 CVE Published
- Jun 28, 2025 PoC Published
- Jun 29, 2025 EPSS Score
- Jun 29, 2025 Coalition ESS Score
- Jun 30, 2025 Coalition ESS Score
- Jun 30, 2025 Coalition ESS Score
- Jun 30, 2025 CVE Updated
- Jun 30, 2025 PoC Published
- Jul 9, 2025 EPSS Score
- Jul 19, 2025 EPSS Score
- Jul 29, 2025 EPSS Score
- Aug 8, 2025 EPSS Score
References
- https://deb.debian.org/debian/pool/main/z/zulucrypt/zulucrypt_6.2.0-1.dsc advisory
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1108288 advisory
- https://salsa.debian.org/debian/zulucrypt/-/blob/9d661c9f384c4d889d3387944e14ac70cfb9684b/debian/patches/fix_zulupolkit_policy.patch advisory
- https://bugs.debian.org/1108288 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-53391 advisory