AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2025-23395

HIGH · CVSS 7.8 EPSS 0.20%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2025-05-26 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 7.8. See the original NVD description below for full technical details.

CVE
CVE-2025-23395
Severity
HIGH
CVSS
7.8
EPSS
0.20%

Original NVD Description

Screen 5.0.0 when it runs with setuid-root privileges does not drop privileges while operating on a user supplied path. This allows unprivileged users to create files in arbitrary locations with `root` ownership, the invoking user's (real) group ownership and file mode 0644. All data written to the Screen PTY will be logged into this file, allowing to escalate to root privileges