🔐 CVE Alert

CVE-2012-10022

UNKNOWN 0.0

Kloxo <= 6.1.12 Local Privilege Escalation

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Kloxo versions 6.1.12 and earlier contain two setuid root binaries—lxsuexec and lxrestart—that allow local privilege escalation from uid 48. The lxsuexec binary performs a uid check and permits execution of arbitrary commands as root if the invoking user matches uid 48. This flaw enables attackers with Apache-level access to escalate privileges to root without authentication.

CWE CWE-269
Vendor lxcenter
Product kloxo
Published Aug 1, 2025
Last Updated Apr 7, 2026
Stay Ahead of the Next One

Get instant alerts for lxcenter kloxo

Be the first to know when new unknown vulnerabilities affecting lxcenter kloxo are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

LxCenter / Kloxo
* ≤ 6.1.12

References

NVD ↗ CVE.org ↗ EPSS Data ↗
raw.githubusercontent.com: https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/linux/local/kloxo_lxsuexec.rb exploit-db.com: https://www.exploit-db.com/exploits/25406 web.archive.org: https://web.archive.org/web/20121122063935/http://roothackers.net/showthread.php?tid=92 kloxo.org: https://kloxo.org/ github.com: https://github.com/KloxoNGCommunity/kloxo vulncheck.com: https://www.vulncheck.com/advisories/kloxo-local-priv-esc

Credits

HTP